diff --git a/addons/hr_timesheet/models/hr_timesheet.py b/addons/hr_timesheet/models/hr_timesheet.py index 8bed71abac0..e9d887d28e8 100644 --- a/addons/hr_timesheet/models/hr_timesheet.py +++ b/addons/hr_timesheet/models/hr_timesheet.py @@ -123,6 +123,15 @@ class AccountAnalyticLine(models.Model): for line in self: line.department_id = line.employee_id.department_id + def _check_can_write(self, values): + # If it's a basic user then check if the timesheet is his own. + if not (self.user_has_groups('hr_timesheet.group_hr_timesheet_approver') or self.env.su) and any(self.env.user.id != analytic_line.user_id.id for analytic_line in self): + raise AccessError(_("You cannot access timesheets that are not yours.")) + + def _check_can_create(self): + # override in other modules to check current user has create access + pass + @api.model_create_multi def create(self, vals_list): # Before creating a timesheet, we need to put a valid employee_id in the vals @@ -193,15 +202,14 @@ class AccountAnalyticLine(models.Model): # 5/ Finally, create the timesheets lines = super(AccountAnalyticLine, self).create(vals_list) + lines._check_can_create() for line, values in zip(lines, vals_list): if line.project_id: # applied only for timesheet line._timesheet_postprocess(values) return lines def write(self, values): - # If it's a basic user then check if the timesheet is his own. - if not (self.user_has_groups('hr_timesheet.group_hr_timesheet_approver') or self.env.su) and any(self.env.user.id != analytic_line.user_id.id for analytic_line in self): - raise AccessError(_("You cannot access timesheets that are not yours.")) + self._check_can_write(values) values = self._timesheet_preprocess(values) if values.get('employee_id'): diff --git a/addons/project_timesheet_holidays/models/account_analytic.py b/addons/project_timesheet_holidays/models/account_analytic.py index b53a9585220..ccc00ba1c89 100644 --- a/addons/project_timesheet_holidays/models/account_analytic.py +++ b/addons/project_timesheet_holidays/models/account_analytic.py @@ -36,16 +36,12 @@ class AccountAnalyticLine(models.Model): action = self._get_redirect_action() raise RedirectWarning(warning_msg, action, _('View Time Off')) - @api.model_create_multi - def create(self, vals_list): - if not self.env.su: - task_ids = [vals['task_id'] for vals in vals_list if vals.get('task_id')] - has_timeoff_task = self.env['project.task'].search_count([('id', 'in', task_ids), ('is_timeoff_task', '=', True)], limit=1) > 0 - if has_timeoff_task: - raise UserError(_('You cannot create timesheets for a task that is linked to a time off type. Please use the Time Off application to request new time off instead.')) - return super().create(vals_list) - - def write(self, vals): - if not self.env.su and self.filtered('holiday_id'): + def _check_can_write(self, values): + if not self.env.su and self.holiday_id: raise UserError(_('You cannot modify timesheets that are linked to time off requests. Please use the Time Off application to modify your time off requests instead.')) - return super().write(vals) + return super()._check_can_write(values) + + def _check_can_create(self): + if not self.env.su and any(task.is_timeoff_task for task in self.task_id): + raise UserError(_('You cannot create timesheets for a task that is linked to a time off type. Please use the Time Off application to request new time off instead.')) + return super()._check_can_create() diff --git a/addons/sale_timesheet/models/account.py b/addons/sale_timesheet/models/account.py index 48294ee8e1b..104e1d7901d 100644 --- a/addons/sale_timesheet/models/account.py +++ b/addons/sale_timesheet/models/account.py @@ -86,16 +86,12 @@ class AccountAnalyticLine(models.Model): def _check_timesheet_can_be_billed(self): return self.so_line in self.project_id.mapped('sale_line_employee_ids.sale_line_id') | self.task_id.sale_line_id | self.project_id.sale_line_id - def write(self, values): - # prevent to update invoiced timesheets if one line is of type delivery - self._check_can_write(values) - result = super(AccountAnalyticLine, self).write(values) - return result - def _check_can_write(self, values): + # prevent to update invoiced timesheets if one line is of type delivery if self.sudo().filtered(lambda aal: aal.so_line.product_id.invoice_policy == "delivery") and self.filtered(lambda t: t.timesheet_invoice_id and t.timesheet_invoice_id.state != 'cancel'): if any(field_name in values for field_name in ['unit_amount', 'employee_id', 'project_id', 'task_id', 'so_line', 'amount', 'date']): raise UserError(_('You cannot modify timesheets that are already invoiced.')) + return super()._check_can_write(values) def _timesheet_determine_sale_line(self): """ Deduce the SO line associated to the timesheet line: