[FIX] hr_attendance: do not allow grouping

The user for the kiosk mode must have access to personal information of
the employees. To avoid easily leaking information, prevent grouping.

Fixes #34231
opw-2079330

closes odoo/odoo#38120

Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
This commit is contained in:
Nicolas Martinelli
2019-10-08 08:13:21 +00:00
parent 8d910c59b5
commit e42aa1e344
3 changed files with 17 additions and 1 deletions
@@ -654,6 +654,12 @@ msgstr ""
msgid "Sign out"
msgstr ""
#. module: hr_attendance
#: code:addons/hr_attendance/models/hr_employee.py:155
#, python-format
msgid "Such grouping is not allowed."
msgstr ""
#. module: hr_attendance
#: model_terms:ir.actions.act_window,help:hr_attendance.hr_attendance_action
#: model_terms:ir.actions.act_window,help:hr_attendance.hr_attendance_action_employee
@@ -141,3 +141,9 @@ class HrEmployeeBase(models.AbstractModel):
raise exceptions.UserError(_('Cannot perform check out on %(empl_name)s, could not find corresponding check in. '
'Your attendances have probably been modified manually by human resources.') % {'empl_name': self.sudo().name, })
return attendance
@api.model
def read_group(self, domain, fields, groupby, offset=0, limit=None, orderby=False, lazy=True):
if 'pin' in groupby or 'pin' in self.env.context.get('group_by', '') or self.env.context.get('no_group_by'):
raise exceptions.UserError(_('Such grouping is not allowed.'))
return super(HrEmployeeBase, self).read_group(domain, fields, groupby, offset=offset, limit=limit, orderby=orderby, lazy=lazy)
@@ -11,7 +11,11 @@ var QWeb = core.qweb;
var KioskMode = AbstractAction.extend({
events: {
"click .o_hr_attendance_button_employees": function(){ this.do_action('hr_attendance.hr_employee_attendance_action_kanban'); },
"click .o_hr_attendance_button_employees": function() {
this.do_action('hr_attendance.hr_employee_attendance_action_kanban', {
additional_context: {'no_group_by': true},
});
},
},
start: function () {