From ede7ae8e55e5b08bd2a697dc324bff4aaa7da7d1 Mon Sep 17 00:00:00 2001 From: "Merlin (megu)" Date: Mon, 6 Dec 2021 15:47:25 +0000 Subject: [PATCH] [FIX] hr_holidays: confirm allocation request with no validation needed An employee could not confirm an allocation request of a type that doesn't need validation Steps to reproduce: 1. Connect as admin 2. Install and open the Time Off app 3. Create a time off type in Configuration->Time Off Types with - Requires allocation: Yes - Approval: No validation needed 4. Connect as demo 5. Open the Time Off app and create an allocation request of the type created just before Solution: Add a condition before raising the error that checks the allocation validation type OPW-2683477 closes odoo/odoo#81143 X-original-commit: d985b96ba77f45edee8001d1063f644c99a15ffc Signed-off-by: Guillaume Merlin (megu) --- .../hr_holidays/models/hr_leave_allocation.py | 4 +-- .../tests/test_allocation_access_rights.py | 27 ++++++++++++++++++- 2 files changed, 28 insertions(+), 3 deletions(-) diff --git a/addons/hr_holidays/models/hr_leave_allocation.py b/addons/hr_holidays/models/hr_leave_allocation.py index 849be27d47f..c204e89d82e 100644 --- a/addons/hr_holidays/models/hr_leave_allocation.py +++ b/addons/hr_holidays/models/hr_leave_allocation.py @@ -657,14 +657,14 @@ class HolidaysAllocation(models.Model): raise UserError(_('Only a time off Manager can reset other people allocation.')) continue - if not is_officer and self.env.user != holiday.employee_id.leave_manager_id: + if not is_officer and self.env.user != holiday.employee_id.leave_manager_id and not val_type == 'no': raise UserError(_('Only a time off Officer/Responsible or Manager can approve or refuse time off requests.')) if is_officer or self.env.user == holiday.employee_id.leave_manager_id: # use ir.rule based first access check: department, members, ... (see security.xml) holiday.check_access_rule('write') - if holiday.employee_id == current_employee and not is_manager: + if holiday.employee_id == current_employee and not is_manager and not val_type == 'no': raise UserError(_('Only a time off Manager can approve its own requests.')) if (state == 'validate1' and val_type == 'both') or (state == 'validate' and val_type == 'manager'): diff --git a/addons/hr_holidays/tests/test_allocation_access_rights.py b/addons/hr_holidays/tests/test_allocation_access_rights.py index 863f2dd6161..587c5a7a827 100644 --- a/addons/hr_holidays/tests/test_allocation_access_rights.py +++ b/addons/hr_holidays/tests/test_allocation_access_rights.py @@ -18,7 +18,7 @@ class TestAllocationRights(TestHrHolidaysCommon): cls.employee_emp.parent_id = False cls.employee_emp.leave_manager_id = False - cls.lt_no_validation = cls.env['hr.leave.type'].create({ + cls.lt_no_allocation = cls.env['hr.leave.type'].create({ 'name': 'Validation = HR', 'allocation_validation_type': 'officer', 'requires_allocation': 'no', @@ -39,6 +39,13 @@ class TestAllocationRights(TestHrHolidaysCommon): 'employee_requests': 'no', }) + cls.lt_allocation_no_validation = cls.env['hr.leave.type'].create({ + 'name': 'Validation = user', + 'allocation_validation_type': 'no', + 'requires_allocation': 'yes', + 'employee_requests': 'yes', + }) + def request_allocation(self, user, values={}): values = dict(values, **{ 'name': 'Allocation', @@ -70,6 +77,24 @@ class TestAccessRightsSimpleUser(TestAllocationRights): with self.assertRaises(AccessError): self.request_allocation(self.user_employee.id, values) + def test_simple_user_request_allocation_no_validation(self): + """ A simple user can request and automatically validate an allocation with no validation """ + values = { + 'employee_id': self.employee_emp.id, + 'holiday_status_id': self.lt_allocation_no_validation.id, + } + allocation = self.request_allocation(self.user_employee.id, values) + self.assertEqual(allocation.state, 'validate', "It should be validated") + + def test_simple_user_request_allocation_no_validation_other(self): + """ A simple user cannot request an other user's allocation with no validation """ + values = { + 'employee_id': self.employee_hruser.id, + 'holiday_status_id': self.lt_allocation_no_validation.id, + } + with self.assertRaises(AccessError): + self.request_allocation(self.user_employee.id, values) + def test_simple_user_reset_to_draft(self): """ A simple user can reset to draft only his own allocation """ values = {