[IMP] {hr,sale}_timesheet, _*: make separate method for access
_* = project_timesheet_holidays Before this commit checking validation for creating and writing on timesheet done in create and write method which makes customization difficult for user. So, in this commit check validation for creating and writing on timesheet done in separate method _check_can_create and _check_can_write respectively for timesheet. task-2928942 closes odoo/odoo#100943 Related: odoo/enterprise#31689 Signed-off-by: Xavier Bol (xbo) <xbo@odoo.com>
This commit is contained in:
@@ -123,6 +123,15 @@ class AccountAnalyticLine(models.Model):
|
||||
for line in self:
|
||||
line.department_id = line.employee_id.department_id
|
||||
|
||||
def _check_can_write(self, values):
|
||||
# If it's a basic user then check if the timesheet is his own.
|
||||
if not (self.user_has_groups('hr_timesheet.group_hr_timesheet_approver') or self.env.su) and any(self.env.user.id != analytic_line.user_id.id for analytic_line in self):
|
||||
raise AccessError(_("You cannot access timesheets that are not yours."))
|
||||
|
||||
def _check_can_create(self):
|
||||
# override in other modules to check current user has create access
|
||||
pass
|
||||
|
||||
@api.model_create_multi
|
||||
def create(self, vals_list):
|
||||
# Before creating a timesheet, we need to put a valid employee_id in the vals
|
||||
@@ -193,15 +202,14 @@ class AccountAnalyticLine(models.Model):
|
||||
|
||||
# 5/ Finally, create the timesheets
|
||||
lines = super(AccountAnalyticLine, self).create(vals_list)
|
||||
lines._check_can_create()
|
||||
for line, values in zip(lines, vals_list):
|
||||
if line.project_id: # applied only for timesheet
|
||||
line._timesheet_postprocess(values)
|
||||
return lines
|
||||
|
||||
def write(self, values):
|
||||
# If it's a basic user then check if the timesheet is his own.
|
||||
if not (self.user_has_groups('hr_timesheet.group_hr_timesheet_approver') or self.env.su) and any(self.env.user.id != analytic_line.user_id.id for analytic_line in self):
|
||||
raise AccessError(_("You cannot access timesheets that are not yours."))
|
||||
self._check_can_write(values)
|
||||
|
||||
values = self._timesheet_preprocess(values)
|
||||
if values.get('employee_id'):
|
||||
|
||||
@@ -36,16 +36,12 @@ class AccountAnalyticLine(models.Model):
|
||||
action = self._get_redirect_action()
|
||||
raise RedirectWarning(warning_msg, action, _('View Time Off'))
|
||||
|
||||
@api.model_create_multi
|
||||
def create(self, vals_list):
|
||||
if not self.env.su:
|
||||
task_ids = [vals['task_id'] for vals in vals_list if vals.get('task_id')]
|
||||
has_timeoff_task = self.env['project.task'].search_count([('id', 'in', task_ids), ('is_timeoff_task', '=', True)], limit=1) > 0
|
||||
if has_timeoff_task:
|
||||
raise UserError(_('You cannot create timesheets for a task that is linked to a time off type. Please use the Time Off application to request new time off instead.'))
|
||||
return super().create(vals_list)
|
||||
|
||||
def write(self, vals):
|
||||
if not self.env.su and self.filtered('holiday_id'):
|
||||
def _check_can_write(self, values):
|
||||
if not self.env.su and self.holiday_id:
|
||||
raise UserError(_('You cannot modify timesheets that are linked to time off requests. Please use the Time Off application to modify your time off requests instead.'))
|
||||
return super().write(vals)
|
||||
return super()._check_can_write(values)
|
||||
|
||||
def _check_can_create(self):
|
||||
if not self.env.su and any(task.is_timeoff_task for task in self.task_id):
|
||||
raise UserError(_('You cannot create timesheets for a task that is linked to a time off type. Please use the Time Off application to request new time off instead.'))
|
||||
return super()._check_can_create()
|
||||
|
||||
@@ -86,16 +86,12 @@ class AccountAnalyticLine(models.Model):
|
||||
def _check_timesheet_can_be_billed(self):
|
||||
return self.so_line in self.project_id.mapped('sale_line_employee_ids.sale_line_id') | self.task_id.sale_line_id | self.project_id.sale_line_id
|
||||
|
||||
def write(self, values):
|
||||
# prevent to update invoiced timesheets if one line is of type delivery
|
||||
self._check_can_write(values)
|
||||
result = super(AccountAnalyticLine, self).write(values)
|
||||
return result
|
||||
|
||||
def _check_can_write(self, values):
|
||||
# prevent to update invoiced timesheets if one line is of type delivery
|
||||
if self.sudo().filtered(lambda aal: aal.so_line.product_id.invoice_policy == "delivery") and self.filtered(lambda t: t.timesheet_invoice_id and t.timesheet_invoice_id.state != 'cancel'):
|
||||
if any(field_name in values for field_name in ['unit_amount', 'employee_id', 'project_id', 'task_id', 'so_line', 'amount', 'date']):
|
||||
raise UserError(_('You cannot modify timesheets that are already invoiced.'))
|
||||
return super()._check_can_write(values)
|
||||
|
||||
def _timesheet_determine_sale_line(self):
|
||||
""" Deduce the SO line associated to the timesheet line:
|
||||
|
||||
Reference in New Issue
Block a user