[IMP] hr: remove schedule on public employee
This commit removes the resource_calendar_id field on the public employee, as this is giving information that we don't necessarily want to be public. Additionnaly, it led to the possibility for every user to access calendar forms. task-3519805 closes odoo/odoo#137211 Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
This commit is contained in:
@@ -13,7 +13,7 @@ from markupsafe import Markup
|
||||
from odoo import api, fields, models, _
|
||||
from odoo.exceptions import ValidationError, AccessError
|
||||
from odoo.osv import expression
|
||||
from odoo.tools import format_date, Query
|
||||
from odoo.tools import format_date
|
||||
|
||||
|
||||
class HrEmployeePrivate(models.Model):
|
||||
|
||||
@@ -28,7 +28,6 @@ class HrEmployeePublic(models.Model):
|
||||
work_location_id = fields.Many2one(readonly=True)
|
||||
user_id = fields.Many2one(readonly=True)
|
||||
resource_id = fields.Many2one(readonly=True)
|
||||
resource_calendar_id = fields.Many2one(readonly=True)
|
||||
tz = fields.Selection(readonly=True)
|
||||
color = fields.Integer(readonly=True)
|
||||
|
||||
|
||||
@@ -90,9 +90,6 @@
|
||||
<group name="managers" string="Approvers" invisible="1">
|
||||
<!-- overridden in other modules -->
|
||||
</group>
|
||||
<group string="Schedule" groups="base.group_no_one">
|
||||
<field name="resource_calendar_id"/>
|
||||
</group>
|
||||
</div>
|
||||
</div>
|
||||
</page>
|
||||
|
||||
Reference in New Issue
Block a user