From eb0d81eaa707a500f67f0e63d4aa2e057cc1291d Mon Sep 17 00:00:00 2001 From: Kartik Chavda Date: Thu, 1 Sep 2022 12:08:26 +0000 Subject: [PATCH] [IMP] {hr,sale}_timesheet, _*: make separate method for access _* = project_timesheet_holidays Before this commit checking validation for creating and writing on timesheet done in create and write method which makes customization difficult for user. So, in this commit check validation for creating and writing on timesheet done in separate method _check_can_create and _check_can_write respectively for timesheet. task-2928942 closes odoo/odoo#100943 Related: odoo/enterprise#31689 Signed-off-by: Xavier Bol (xbo) --- addons/hr_timesheet/models/hr_timesheet.py | 14 ++++++++++--- .../models/account_analytic.py | 20 ++++++++----------- addons/sale_timesheet/models/account.py | 8 ++------ 3 files changed, 21 insertions(+), 21 deletions(-) diff --git a/addons/hr_timesheet/models/hr_timesheet.py b/addons/hr_timesheet/models/hr_timesheet.py index 8bed71abac0..e9d887d28e8 100644 --- a/addons/hr_timesheet/models/hr_timesheet.py +++ b/addons/hr_timesheet/models/hr_timesheet.py @@ -123,6 +123,15 @@ class AccountAnalyticLine(models.Model): for line in self: line.department_id = line.employee_id.department_id + def _check_can_write(self, values): + # If it's a basic user then check if the timesheet is his own. + if not (self.user_has_groups('hr_timesheet.group_hr_timesheet_approver') or self.env.su) and any(self.env.user.id != analytic_line.user_id.id for analytic_line in self): + raise AccessError(_("You cannot access timesheets that are not yours.")) + + def _check_can_create(self): + # override in other modules to check current user has create access + pass + @api.model_create_multi def create(self, vals_list): # Before creating a timesheet, we need to put a valid employee_id in the vals @@ -193,15 +202,14 @@ class AccountAnalyticLine(models.Model): # 5/ Finally, create the timesheets lines = super(AccountAnalyticLine, self).create(vals_list) + lines._check_can_create() for line, values in zip(lines, vals_list): if line.project_id: # applied only for timesheet line._timesheet_postprocess(values) return lines def write(self, values): - # If it's a basic user then check if the timesheet is his own. - if not (self.user_has_groups('hr_timesheet.group_hr_timesheet_approver') or self.env.su) and any(self.env.user.id != analytic_line.user_id.id for analytic_line in self): - raise AccessError(_("You cannot access timesheets that are not yours.")) + self._check_can_write(values) values = self._timesheet_preprocess(values) if values.get('employee_id'): diff --git a/addons/project_timesheet_holidays/models/account_analytic.py b/addons/project_timesheet_holidays/models/account_analytic.py index b53a9585220..ccc00ba1c89 100644 --- a/addons/project_timesheet_holidays/models/account_analytic.py +++ b/addons/project_timesheet_holidays/models/account_analytic.py @@ -36,16 +36,12 @@ class AccountAnalyticLine(models.Model): action = self._get_redirect_action() raise RedirectWarning(warning_msg, action, _('View Time Off')) - @api.model_create_multi - def create(self, vals_list): - if not self.env.su: - task_ids = [vals['task_id'] for vals in vals_list if vals.get('task_id')] - has_timeoff_task = self.env['project.task'].search_count([('id', 'in', task_ids), ('is_timeoff_task', '=', True)], limit=1) > 0 - if has_timeoff_task: - raise UserError(_('You cannot create timesheets for a task that is linked to a time off type. Please use the Time Off application to request new time off instead.')) - return super().create(vals_list) - - def write(self, vals): - if not self.env.su and self.filtered('holiday_id'): + def _check_can_write(self, values): + if not self.env.su and self.holiday_id: raise UserError(_('You cannot modify timesheets that are linked to time off requests. Please use the Time Off application to modify your time off requests instead.')) - return super().write(vals) + return super()._check_can_write(values) + + def _check_can_create(self): + if not self.env.su and any(task.is_timeoff_task for task in self.task_id): + raise UserError(_('You cannot create timesheets for a task that is linked to a time off type. Please use the Time Off application to request new time off instead.')) + return super()._check_can_create() diff --git a/addons/sale_timesheet/models/account.py b/addons/sale_timesheet/models/account.py index 48294ee8e1b..104e1d7901d 100644 --- a/addons/sale_timesheet/models/account.py +++ b/addons/sale_timesheet/models/account.py @@ -86,16 +86,12 @@ class AccountAnalyticLine(models.Model): def _check_timesheet_can_be_billed(self): return self.so_line in self.project_id.mapped('sale_line_employee_ids.sale_line_id') | self.task_id.sale_line_id | self.project_id.sale_line_id - def write(self, values): - # prevent to update invoiced timesheets if one line is of type delivery - self._check_can_write(values) - result = super(AccountAnalyticLine, self).write(values) - return result - def _check_can_write(self, values): + # prevent to update invoiced timesheets if one line is of type delivery if self.sudo().filtered(lambda aal: aal.so_line.product_id.invoice_policy == "delivery") and self.filtered(lambda t: t.timesheet_invoice_id and t.timesheet_invoice_id.state != 'cancel'): if any(field_name in values for field_name in ['unit_amount', 'employee_id', 'project_id', 'task_id', 'so_line', 'amount', 'date']): raise UserError(_('You cannot modify timesheets that are already invoiced.')) + return super()._check_can_write(values) def _timesheet_determine_sale_line(self): """ Deduce the SO line associated to the timesheet line: