Commit Graph
103 Commits
Author SHA1 Message Date
Kevin Baptiste ba619ce027 [IMP] hr_holidays: allow users to cancel Time Off
A user without Time Off rights is now allowed to cancel their own
validated time off when:
    - It's not yet started;
    - No work-entries has been generated for it yet.

The time off is archived and the days taken reallocated.

closes odoo/odoo#76722

Taskid: 2643713
Related: odoo/upgrade#2843
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-10-28 11:34:57 +00:00
254d6a71e8 [IMP] hr_holidays: Improve Accruals, dashboards and general UX (Back2basics)
Purpose
=======

Time Off : New Dashboard, Accruals feature, Public holidays, New time off type configuration view.

- Review of Dashboard
- Accrual feature : Currently, when you create an allocation, it's possible to create an
  Accrual, but there is no appraisal Plan. An Appraisal plan is use to define steps of accruals
  for each employee.
  In Belgium, we use accrual Allocation for European Leaves, or compensatory hours, it's a
  simple use case.  But in USA, it's possible to change the calculation mode each year.
  Also, in USA, it's possible to deal your accrual plan when you arrive on the company. It's a
  HR Officer task to create the right Accrual allocation for each new employee.
- Public Holidays :
  Improvement of global time off feature located on Working hours calendar. Now, Time off
  application have to manage Public Holidays.
- Review of Time Off type configuration

COM PR: https://github.com/odoo/odoo/pull/72511
ENT PR: https://github.com/odoo/enterprise/pull/19157
UPG PR: https://github.com/odoo/upgrade/pull/2791
TaskID:2475413

closes odoo/odoo#72511

Related: odoo/enterprise#19157
Related: odoo/upgrade#2791
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
Co-authored-by: William Braeckman <wbr@odoo.com>
Co-authored-by: Xavier BOL (xbo) <xbo@odoo.com>
Co-authored-by: Laurent Stukkens (LTU) <ltu@odoo.com>
Co-authored-by: Yannick Tivisse <yti@odoo.com>
2021-09-02 12:57:03 +00:00
Touati Djamel (otd) 7ed01a437f [FIX] hr_holidays: fix time off allocation access right
Steps to reproduce the problem:
- Connect as admin
- Create a new employee, e.g: “Employee1” for company “My Company (San Francisco)”
- Create a new time off request for this employee, and select a time off type linked to the company "San Francisco"
- create a user and do not give him access to the company “San Francisco”, e.g: “user1”
- Log in as “user1”
- Go to time off > Managers > Allocations > remove default filter

Problem:
user1 is able to see the time off allocation of “Employee1”, even though he does not have access to My Company San Francisco.

Solution:
Add multi-company rules  for the “hr.leave_allocation” model to display only the time off allocations to which the current user has access

A rule has already been added for "hr.leave" model:
https://github.com/odoo/odoo/blob/0f3281e3b1dc943b81d79d2a8f82fca7b95b8186/addons/hr_holidays/security/hr_holidays_security.xml#L65-L70

opw-2535709

closes odoo/odoo#75211

closes odoo/odoo#75725

X-original-commit: 90ef15043c7d9c35a22dd7f3c10c78774b6e816a
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Djamel Touati <DjamelTouati@users.noreply.github.com>
2021-08-31 07:31:39 +00:00
Touati Djamel (otd) f36520e12f [FIX] hr_holidays: fix time off allocation access right
Steps to reproduce the problem:
- Connect as admin
- Create a new employee, e.g: “Employee1” for company “My Company (San Francisco)”
- Create a new time off request for this employee, and select a time off type linked to the company "San Francisco"
- create a user and do not give him access to the company “San Francisco”, e.g: “user1”
- Log in as “user1”
- Go to time off > Managers > Allocations > remove default filter

Problem:
user1 is able to see the time off allocation of “Employee1”, even though he does not have access to My Company San Francisco.

Solution:
Add multi-company rules  for the “hr.leave_allocation” model to display only the time off allocations to which the current user has access

A rule has already been added for "hr.leave" model:
https://github.com/odoo/odoo/blob/0f3281e3b1dc943b81d79d2a8f82fca7b95b8186/addons/hr_holidays/security/hr_holidays_security.xml#L65-L70

opw-2535709

closes odoo/odoo#75220

X-original-commit: a6f951845d5de869b2e138403aecfd4c653bf8b3
Signed-off-by: Nicolas Lempereur (nle) <nle@odoo.com>
Signed-off-by: Djamel Touati <DjamelTouati@users.noreply.github.com>
2021-08-17 17:39:13 +00:00
Nisha patel adf3c610c7 [FIX] hr_holidays: Improve displayed information on calendar leaves
See task pad for complete information.

closes odoo/odoo#58168

Taskid: 2314838
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-03-10 14:21:24 +00:00
sofiagvaladze 21e2676b7a [IMP] hr_holidays: Allow to delete future time off
Allow to delete a non validated time off in the future to a simple user
Add some tests

Task - 2428789

closes odoo/odoo#65361

Related: odoo/upgrade#2127
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2021-02-16 09:44:15 +00:00
Arnaud Baes c618561c03 [FIX] hr_holidays: write access for approvers
Without write permissions, Time Off Managers are unable to approve
nor refuse leave requests. It seems there was a mismatch with
`hr_holidays.group_hr_holidays_user` as "Approvers" and actual users
at some point.

Bug reported via p/feedback by CMO and LEM after v14.0 migration.

closes odoo/odoo#62084

X-original-commit: 7c32f977aa5233d47ba6aebef56dc70f7b7b9bac
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-11-20 11:06:34 +00:00
sahista pathan 5a028bd6ab [IMP] hr_holidays: time off responsible
PURPOSE

On the user rights screen, we can't choose responsible.
It shouldn't be visible.

SPECIFICATIONS

A "Time off Responsible" rights will be implicited as a checkbox in debug mode.
Also, changed "Manager" by "Approver" on Time Off type settings.

LINKS

PR https://github.com/odoo/odoo/pull/56807
Task-2314833

closes odoo/odoo#56807

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-09-02 06:36:42 +00:00
Nicolas Martinelli 42ddda0023 [FIX] hr_holidays: duplicated id
2 record rules have the same id, which is typo.

opw-2242566

closes odoo/odoo#49938

X-original-commit: cdd0d02a160b10e90c8fc7569ff2ca99ea879f89
Signed-off-by: Nicolas Martinelli (nim) <nim@odoo.com>
2020-04-22 08:59:10 +00:00
Kevin Baptiste b8a8ad27de [FIX] hr_holidays: "Everyone" view on calendar_event
Purpose
=======

Avoid to show to much information to leave responsibles.

Specification
=============

- Dynamically add/remove the leave_manager_ids on the group
  group_hr_holidays_responsible, on employee creation/modification
- Retrict the available employees when creating a leave. For
  manager/users : Everyone. For responsibles: The employee for
  who the user is responsible. Otherwise: Only me.
- Don't obfuscate the leave name on employees for who I'm the
  responsible.
- Add a new SQL view for "Everyone" report. To select only the
  information we want to share instead of showing the hr.leave
  model directly.

closes odoo/odoo#47659

closes odoo/odoo#49765

Taskid: 2206862
Related: odoo/enterprise#9239
Related: odoo/enterprise#10021
X-original-commit: 781147dcaf1552b8f2ab687ed73034b8fd1f7352
Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2020-04-20 09:19:48 +00:00
Victor Feyens a3ded9043d [IMP] *: declare ir.rule in noupdate
ir.rule are default values but can be customized based on the
company's policy and needs.
This is typically a record that is in noupdate as should be
customization-friendly.
2020-03-20 16:21:25 +01:00
Victor Feyens 532c083cbb [IMP] *: remove global field definition in ir rules xml
It is a computed field, there is no need to manually set its value.
2020-03-20 16:15:40 +01:00
Martin Trigaux 65530dfd6a [ADD] *: add ir.model.access on all transient models
Following changes needing ir.model.access on transient models too.
Remove groups declaration on the action to move it to ir.model.access
when possible.
Rules are strict by default with no unlink access by default and high
priviledge asked. Adaptations may be needed later.
Write access is given as a wizard may need to be modified in case the
action triggers an error and the user has to correct a value

account*: use account.group_account_user for all transient by default
	  remove account.print.journal relic
stock*: use stock.group_stock_user by default
survey: survey user can send invitations
mail: allow any employee to execute wizards
      additional verifications are made to ensure they are executed
      only on the documents the user has access to you
      give portal access to mail.compose.message as portal still does
      some actions like posting messages on the forum
      add ir.rule to avoid reading somebody else messages
      increase the query count because of undeterminist count
crm: saleman for lead2opp, manager for massmailing
     partner manager for actions linked to partners
     avoid a write in test_lead_lost
sms: any employee can send sms
mrp: mrp user can execute wizards
     give unlink access as making write during do_produce operation
base_import: employees can import files
delivery: stock user can deliver
event_sale: sale user can configure the wizards
	    event user inherit from  sale rights
gamification: employee can give badge
google_service: resolve FIXME
hr: add specific rights
    manager can set a plan according to group on button
    anyone who can write on an employee can register a departure
hr_expense: set rights based on buttons
hr_holidays: an approver can make a summary report
hr_recruitment: recruiter can refuse a candidate
hr_timesheet: can use the wizard if can create a timesheet
l10n_eu_service: managers can create fiscal positions
mass_mailing: same group as on mass.mailing.list
membership: accountant can create invoice from membership
payment: accountant can create a link
	 as the source is an account.move
	 keep the payment.acquirer.onboarding.wizard to system user
	 only as it is called during company configuration
point_of_sale: PoS manager only can use wizards
	       never create closing_balance_confirm_wizard records
product_expiry: stock user has rights on stock.picking
product_margin: access from accounting menus
repair: same rules as for above models
sale: set ir.rule for self wizard only
      add rule from model introduced in payment to add salesman group
sale_crm: saleman can create a quotation from a lead
sale_coupon: any saleman can generate coupon
	     add self ir.rule
sale_product_configurator: salesman can select product variants
snailmail: employee can send letters
website: designers can write on website
website_crm_partner_assign: same rule as group on action
website_sale: sale ACL as for payment.acquirer.onboarding.wizard
website_slides: anyone can send invitation

base: base.language.*: allow employee (cf lang_install)
      change.password.user: can not read change password wizard of
      other users
      test.*: no access is needed

Courtesy of Damien Bouvy, William Andre and Antoine Prieëls for review
of acl
2020-02-04 17:54:18 +01:00
Lucas Lefèvre 8f3a5068ca [IMP] hr_holidays: Add specific approval for allocations
Purpose
=======

We want to allow different approvals for allocations and leaves of a same type.

e.g. In case of compensation days, a manager would approve the
allocation request, but would later not approve leave requests.

Specification
=============

Allocation modes
----------------
No change here except renames.
1. No limit (employee doesn't need an allocation to request a leave)
2. Allow employee requests
3. Fixed by Time Off Officer

Allocation approval
-------------------
A radio field to choose the approval mechanism
appears if the employee is allowed to request an allocation.
The following approval modes are possible:
1. Time Off Officer
2. Employee's Time Off Manager (leave_responsible_id)
3. Employee's Time Off Manager and Time Off Officer

These options are the same as leave approval options
(except the missing "No Validation").

If option 1 or 2 is selected, a o2m field should
allow to select which Time Off Officer is responsible
for approving those allocations.

Allocation approval policy is the same as the leave approval policy.

Task id: 1936742

Access rights based on task 1950998
2019-11-22 16:58:38 +01:00
RomainLibert 72817914b5 [FIX] hr_holidays: Uniformize allocation validation for responsibles
Purpose
=======

Have the same mechanism for time off responsibles between leaves and allocations.
2019-09-11 09:27:42 +00:00
RomainLibert e0b16b22e8 [IMP] hr_holidays: Improve general UX (back2basics)
Purpose
=======

Having a clean policy in leave access right. If there
are some internal need or bugs, read this before decided
if it is an expected brhavior or not. It is what we want
in a standrard point of vew.

Specification
=============

Access rights Policy
--------------------

Remove Time Off - Team Leader access right

Leave_manager_id is now requried, by default it
is = parent_id for admin it is admin by default (data
employee_admin)

3 access rights:
- Internal User
- Time Off - All Approver
- Time Off - Administrator

3 fields for "manager"
- parent_id
- leave_manager_id
- manager_id on department

Department
Is just there for information. So never use it in
default filters

Rules Policy
------------

Don't forget to take the leave type configuration into
account
* no validation means automatic
* officer validation means you need to be at least
holidays_user to approve
* manager validation means anyone who is at least
leave_manager_id can approve

Internal User
-------------

In double validation mode he:
- can only do the first approval
- can see the everyone's leaves with a anonymisation of
the leave description
- can create a leave (even if leave type is directly approved)
- can refuse its own leaves (till not reported in payslip)
- can reset to draft his own leaves and reconfirm them
- can delete a leave in draft state
- can cancel a leave if the date_start is in the future
- cannot validate its own leaves

If leave type is configured in manager mode, he:
- can approve or refuse the leaves if he is leave_manager_id

If leave type is configured in both mode, he:
- can only do the first approval or refuse for the leave
if he is leave_manager_id

Time Off - All Approver
-----------------------

In double validation mode he:
- can only do the second approval
- can see, write, read all leaves and perform the second
approval.
- Can set a leaves as reported in payslip.
- Cannot validate its own leaves
- cannot configure leave type
- cannot create leaves in batch

Time Off - Administrator
------------------------

In double validation mode he:
- can do all the approvals
- can bypass all leaves (approve or refuse).
- can configure Time Off Types
- can create batch leaves
- can validate its own leaves

Menu
----

- My Time Off (access rights: internal user)
- Dashboard
- Time Off Requests
- Allocation Requests
- My Team (rename into "Everyone", access rights: internal
user. default filters on current year and group by
employee; default view: gantt can switch to list and form)
- Managers
- To Approve (internal user who are leave_manager_id
see and can approve. See only leave he has to approve
(domain))
- Time Off
- Allocation
- All
- Time Off
- Allocation
- Payroll
- Time Off to report.
- Reporting (access right: time off administrator)
- Time Off Analysis
- Report by Department
- Configuration (access right: time off administrator)

Usability
---------

- In all list of "manager menus", add actions to change
status in mass
- In leave type data:
- move Home Working from data to demo data
- There are 2 Paid time off, get rid of the company on
it and share it on all companies (keep only the one
in data)
- Leave type like this:
- Overtime Compensation/compensatory days (keep only
one of both, to avoid having 2 same leaves in
demo data). Validation by: team leader and hr
officer, no validity date
- Paid Time Off 2019. Validation by Team Leader
and Payroll Officer. Remove validity, remove 2019.
- Unpaid. Can be taken in hours. Approved by Payroll
officer and team leader. No allocation needed.
- New leave request: order of leave type in the m2o:
1. leaves where allocation are fixed by rh and remaining
> 0 and allocated > 0
2. leaves where free allocation. Where reaming is > 0
and allocated >0
3. One already taken
4. All other leaves.
- Remove the sequence widget in leave type
- The employee should get a notification when his leave is
refused "Your "leave_type_name_" planned on "start_date"
has been refused"
- from the dashboard calendar, the reset to draft should lead
to edit (avoid user has to click on edit)
- An employee should be notified when a leave is approved
"Your [leave_type_name] on [start date] has been approved"

Leave Dashboard V2
------------------

https://drive.google.com/file/d/1pMCqDlecqM7ngvmhJJdWtkG2_GiXHyIX/view?usp=sharing

Testing
-------

Everything concerning the leave requests has to be tested.
All the access rights have been reviewed and need testing.

Migration
---------

Don't forget to keep the filters in the calendar view (otherwise RIP perfomances and usability)

TaskID: 1950998

closes odoo/odoo#33813

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-07-23 08:21:55 +00:00
Yannick Tivisse a5b6f31cf2 [IMP] base: Contextualize the multi company
Purpose
=======

Allow the user to select the allowed companies for which he wants to see records
on top of selecting his current company.

It is confusing for users to see the records from the company he is connected to
and the records of the children companies.

Instead of using the hierarchy of companies to access records across companies,
the user can now select (from his set of allowed companies) the companies for
which he wants to access records.

/!\ This means that the user will interact with records from company A when in
company B.
Example: a SO has been created and confirmed in A. When in B, I create the
invoice from it.

Specifications
==============

1/ Deprecate the parent/children hierarchy on the res.company model. The fields are
kept on the res.company model to ensure the retro-compatibility, but won't be used
accross the standard code anymore. The only functional usage for this mechanism
was to allow to see records from several companies by creating a virtual parent
company, which will be possible with the new mechanism.

2/ By default, a user will only see the records of the company he is connected
to (or records without a company). (It is still editable by the user if needed).
For that, put this information in the user context, to allow having different
configurations on different browser tabs. Instead of having domains like
['|',
('company_id', '=', False),
('company_id', 'child_of', user.company_id.id)]
you'll have something like
['|',
('company_id', '=', False),
('company_id', 'in', company_ids)]
Note that the 'company_ids' is a value that is passed in the evaluation
context on the record rule, as we already have user, or time.
company_ids is a list of the ids of all the enabled companies in the
user's context.

3/ Out of the generic improvements brought by this task, this will illustrate
issues that could exist since several versions. For example, it should not be
possible to create a scrap order for the company A with a package of the company
B, or it should not be possible to create an invoice on the company A with
payment terms from the company B. Before the version 12.0, it was easy to
encounter this kind of issues as the admin was the SUPERUSER_ID. A positive side
effect of the fact that the SUPERUSER_ID has become an inactive user was to
make it more difficult to introduce mismatch on the records, but haven't solved
the issue, as it was still possible to do it with parent companies
configuration. Some of these issues have been fixed in this commit, but all the
business flows should be re-tested to check if an ir.rule should be introduced
(eg: a multi company rule for stock.quand.package), if the company of a record
is correctly transfered to another record created from the first record (eg:
From a SO, create an invoice and a payment, the company of the sales order
should be transfered on the invoice and the payment, even if the company of the
sales order is A and I'm logged into the company B with the company A enabled.

4/ Currently, if I click on a button on a notification email (example 'View
Task'), I face a traceback if I'm not logged into the company of the record.
Now, if you click on a button and if you have access to the record, the correct
company will be automatically set.

5/ If I display a kanban view with several records from several companies (and
an image), all the images should be displayed.

6/ Currently if you copy paste an url, this will crash if you're not in the
correct company. This won't be fixed because it's quite impossible to do it in
a clean way. This task brings a workaround. Copy/Paste -> Traceback -> Log into
the correct company, re-copy/paste -> Ok.

7/ 2 property methods have been added on the environment to retrieve the company
on which the user is logged in and the companies the user enabled, on a specific
tab.
That way, when creating a record, instead of doing
default=lambda self: self.env.user.company_id
do
default=lambda self: self.env.company_id
On the other hand, to retrieve the enabled companies, do
companies = self.env.company_ids

8/ Modify the Company Switcher widget to allow to log into another company
WITHOUT writing on the res.users (and thus bringing cache invalidation issues
and so on). Also allow to enable several companies and see records from several
companies, and independantly of the other browser's tabs.

9/ When focusing on a tab, save the current company configuration on the local
storage. That way, when doing 'CTRL+T' or a middle click, the context is
propagated to the new tab.

10/ Improve the error message in case of multi company access errors. Now, when
the user is in debug mode, display the related names of the records and the name
of the user who brings the issue.

11/ Remove the context erasing when writing on a res.users
This is probably coming from the migration to new API of the base module.
The context was not propagated at this moment, which was a common mistake at
that time. When migrating the module, probably by using the 'black box' method,
as the context was not propagated, it was erased on the new version. This is
now an issue because the context (i.e. the enabled companies) was erased when
writing on a res.users, leading to tracebacks.
See: https://github.com/odoo/odoo/commit/7eab8e26d3d46c53f4be924d6a34e80a66e74960#diff-4c2e738ee8f64f11806c889ea097b5e7R624

12/ Fix the crash manager on redirect warnings. The issue is the following
- Create an invoice on a company without a configured CoA.
- Set a partner
- On the onchange_partner_id, a redirect warning is raised to propose you
to configure a CoA
- Click on 'Go to the configuration panel'
- A generic warning says something like 'Do you want to discard your changes?'
- Click on yes, the page refreshes, but not on the redirect action.
Now, set correctly the action on the hash, and reload instead. The breadcrumb is
lost for example, but you reach the correct action at least.

13/ Introduce a res.group to enable/disable the multi company per tab
feature.

14/ To help the users to know which tab is in which company, add the
possibility to have a favicon per company. When creating a company,
the classical 'O' icon is colored by default in a random color.

15/ Remove the company switcher on the frontend. This was mainly there
to allow a user to swicth to the company linked to the website.
This behavior is now transparent to the user. If the website A is
activated, then the company set on the context is the company of the
website.

16/ Deprecated the _company_default_get method on the res.company
model. Remove the method _get_company on the res.users model.

17/ Add 'allowed_company_ids' and 'current_company_id' on the pyeval
context. You can now use those variables on domains in the views to
access directly to the activated company.ies on the current tab.

TaskID: 1960971

closes odoo/odoo#32341

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-05-13 08:57:49 +00:00
Lucas Lefèvre f1fca6dc81 [FIX] hr_holidays: Group team leader imply group user
Currently, group Team Leader does not imply group user.
However a team leader is always a user and should be member of
the corresponding group.
2019-03-19 09:33:07 +01:00
Christophe Simonis 44515bc7be [MERGE] forward port branch saas-12.2 up to c9f832d9f0
closes odoo/odoo#31790

Signed-off-by: Christophe Simonis <chs@odoo.com>
2019-03-13 14:24:51 +00:00
Christophe Simonis 71faa19af0 [MERGE] forward port branch saas-12.1 up to 2b3296bbf8 2019-03-11 14:42:34 +01:00
RomainLibert 8c7970bf8f [IMP] hr_holidays: reintroduce no_validation leave_type
Since https://github.com/odoo/odoo/commit/59956805424808beed82f1afa5c5e6996e34eb13#diff-ab6382882079a64a861bbba2741a1075 it was impossible to use the no_validation
on hr_leave_type.

This commit reintroduces this possibility and ensures the leave user gets
an actvity for the leave

This commit also add a field on hr_leave_type in order to know for whom
we should create the activity when validation is by hr

closes odoo/odoo#30807

Signed-off-by: Yannick Tivisse (yti) <yti@odoo.com>
2019-03-06 11:59:27 +00:00
Toufik Ben Jaa e4c434c6ff [FIX] hr_holidays: inconsistency in leave record rules
- `hr.leave` and `hr.leave.allocation` should have the same record
  rules, otherwise leave approval behavior can be unpredictable.

  As a Holidays Team Leader:
    For example you could see the approve button on a leave but cannot
    approve it because the `_check_holidays` fails

closes odoo/odoo#31620

Signed-off-by: Christophe Simonis (chs) <chs@odoo.com>
2019-03-06 09:03:28 +00:00
Toufik Ben Jaa 2bebbdefc2 [FIX] hr_holidays: allow employee's manager to approve employee's leaves
- Allow users with the "Holidays Team Leader rights" to approve the
  leaves of the employees they manage.

closes odoo/odoo#31586

Signed-off-by: "Christophe Simonis (chs)" <chs@odoo.com>
2019-03-05 10:45:00 +00:00
Lucas Lefèvre 221caccb70 [FIX] hr_holidays: Group team leader imply group user
Currently, group Team Leader does not imply group user.
However a team leader is always a user and should be member of
the corresponding group.

closes odoo/odoo#31539
2019-03-01 15:05:22 +00:00
Lucas Lefèvre a8ab3063e8 [FIX] hr_holidays: Allow Team leader to approve
Currently, a Team leader can't approve a leave of an employee
in his team if the leave type requires an allocation.

The reason is the `ir.rule` for `base.group_user` restricting allocation
read access to only your own allocation (`[('employee_id.user_id', '=', user.id)]`)
There are no `ir.rule` for group Team leader.
Therefore, a team leader can't read allocations for his team members.

Fix: add an `ir.rule` to allow a team leader to read allocations
of employees in his team.

+ add associated tests
2019-03-01 14:30:39 +00:00
jbm-odoo ec07e72845 [IMP] base,*: Reorganize access rights groups
Purpose
=======

Access group terminology is missleading. Yous have to be manager to administrate
an application. This task consists to rename groups to be understandable for everyone.

Groups should be reorganised on the users form to be more explicit.

Specification
=============

1/ Rename 'Manager' to 'Administrator' in users groups.
2/ Define a hierarchy on access groups by using the category_id in the manifests
   A category 'Operations/Project' will create a category Project with a parent
   category 'Operations', and something smart is already developed (in modules/db.py)
   to avoid duplicating categories.
3/ Add a group in expenses to be able to approve expenses reports for my team.
4/ Add a group in timesheets to be able to approve timesheets for my team.
5/ Remove partially the useless crap in ir_module_category_data.xml
6/ Sort access rights groups on users form according to its parent category

closes odoo/odoo#29362

Signed-off-by: "Yannick Tivisse (yti)" <yti@odoo.com>
2019-03-05 09:08:12 +00:00
jbm-odoo a3daff6bc1 [IMP] hr_holidays: Rename 'leave' into 'time off' + add dashboard
Purpose
=======

We need to use an international word to define holidays and leaves, rename everything into Time Off.
Employees needs a good dashboard and leaves summary

Specification
=============

1/ Add a new dashboard: https://balsamiq.cloud/sm5j0d/pg5w04r
   Create a new dashboard with a calendar and a summary of all time off and time off request
2/ Rename leaves into Time Off everywhere
3/ Improve general usability

TaskID: 1916871

closes odoo/odoo#29634
2019-01-21 11:29:30 +00:00
lbs-odoo c99a6d2fb5 [IMP] hr_holidays: Add team leader group and leave_manager_id
Purpose
=======

1/ A team leader is not able to validate leaves for his own team.
2/ Another person than the manager can be supposed to validate the leaves for a certain employee

Specification
=============

1/ New hierarchy: Team Leader < Officer < Manager

People in Team Leader access group will now be able to approve leaves for employees in their team.

- Added the new access group
- Added rules for people in this group to read or write appropriate records

2/ Add 'leave_manager_id' field on employees to refer to the Team Leader.

- Added the new field to Employee model
- Added the field to the view so that it is visible
- Modified a filter in a view so that it is more relevant according to its name (My Team Leaves)
- Added a filter in a view for managed employees

TaskID: 1888653

closes odoo/odoo#28352
2018-11-07 13:52:37 +00:00
Christophe Simonis 68d36512ef [MERGE] forward port branch saas-11.4 up to d78f23df84 2018-09-07 20:20:45 +02:00
Thibault Delavallée 0f3281e3b1 [REF] hr_holidays: clean leave and allocation access rights
Purpose

 - clean access rights;
 - solve some access and security issues;

Access specifications

 - an user
  - can see all leaves;
  - cannot see name field of leaves belonging to other user as it may contain
    private information that we don't want to share to other people than
    HR people;
  - can modify only its own not validated leaves (except writing on state to
    avoid bypassing validation);
  - can discuss on its leave requests;
 - an Officer
  - can see all leaves;
  - can validate "HR" single validation leaves from people if
   - he is the employee manager;
   - he is the department manager;
   - he is member of the same department;
   - target employee has no manager and no department manager;
  - can validate "Manager" single validation leaves from people if
   - he is the employee manager;
   - he is the department manager;
   - target employee has no manager and no department manager;
  - can first validate "Both" double validation leaves from people like "HR"
    single validation, moving the leaves to validate1 state;
  - cannot validate its own leaves;
 - a Manager
  - can do everything he wants

In top of that, multi company rule are correctly added.

In reporting model using in "summary" name field should also be stripped
if you are not an HR officer and if it is not your own request.

Concerning allocation requests: implement same rules except constraint on
name field as it is less private and therefore can be seen.

This commit is linked to task ID 1876795 and PR #26656.
2018-08-31 14:19:23 +02:00
Thibault Delavallée 0113d989a8 [REV] hr_holidays: revert "[FIX] hr_holidays: officers can CRUD leaves for their companies"
This commit was not correct and was a quick fix to avoid blocking daily use
of odoo saas-11.3. Next commit will fix access rights and enforce their
definition through more detailed tests.

This reverts commit ae34db3221.

This commit is linked to task ID 1876795 and PR #26656 .
2018-08-31 14:19:23 +02:00
Lucas Perais (lpe) ae34db3221 [FIX] hr_holidays: officers can CRUD leaves for their companies
Before this, CRUD leaves was limited to department

After this, we go back to what was in 11.2: CRUD for the whole company, and children of it

OPW 1878869
closes #26516
2018-08-27 10:37:44 +02:00
Raphael Collet 2f7c03d9ca [IMP] base: add regular user admin as uid 2
User 1 simply becomes a technical user (inactive, no password).
2018-08-23 21:38:57 +02:00
RomainLibert c1530f219b [IMP] hr_holidays: improves access rights of manager/officer
We need to have a clear distinction between holidays managers and
holidays officers.
For this a number of improvements have been done in hr_holidays.
For more informations about the changes see the docstrings of hr.leave
and hr.leave.allocation.

Task #34222
Closes #19270
2018-04-09 17:49:51 +02:00
Thibault Delavallée 1d71c06233 [IMP] hr_holidays: improve activity management on leave model
This commit improves leave request and allocation management through a
better integration of activities and addition of automated activities.
Several things are done in this commit :

 * leave and allocation models do not inherit from mail.activity.mixin.
   This commit adds the inherit so that HR users and managers can now
   schedule and manage activities on leave and allocation requests. This
   will help them in their daily job;
 * automatic activities generation is added for leave and allocation.
   Activities are generated for approval and second approval. They are also
   automatically set as done when validating or unlinked when refusing or
   resetting to avoid bloating users with unnecessary activities;
 * a menu to configure activity types is added. Indeed HR managers should be
   able to see and configure activity types related to their job;
 * filters are added to be able to use the systray and to filter the kanban
   view based on activities

Having automated activities allow to replace some messages and tracking
that were implemented to warn people of leave and allocation to approve
or validate. This commit therefore

 * simplifies the tracking as only approved or refused state now trigger
   a subtype;
 * removes to approve and to validate subtypes on leave and allocation
   model as well as their parent subtypes on the department. This allows
   to simplify chatter a lot in hr_holidays app;
2018-03-27 15:19:10 +02:00
RomainLibert f61687a4cd [IMP] hr_holidays : split hr.holidays into hr.leave and hr.leave.allocation
Purpose
=======

Have a clear distinction between leave and allocation requests instead of
using the same model to mix 2 different concepts.

Splitting the model will allow different business code to be run on each
model as allocations and leaves are not exactly the same thing; this
will add some code but simplify future improvements

Specification
=============

1/ Completely separate the models

Model hr.holidays has been split into leave.request and
leave.allocation.

2/ Make reporting working again by using an SQL view aggregating data
from leaves and allocations

A new report has been added in order to aggregate
datas from both allocations and requests. The views have been modified
accordingly.
2018-01-15 10:38:31 +01:00
Dipali Tank 00f90a70ed [IMP] *: holidays -> leaves
The meaning of "holidays" may vary in the UK/US.
2017-08-08 11:53:03 +02:00
Yannick Tivisse bf1bfb06fe [FIX] hr_holidays: Allow a employee to reset to draft his own leaves
If a leave request is refused by the manager, the button reset to draft is displayed, but the employee cannot use it because he doesn't have the write access rights on his own leave requests

In 'refuse' state, all the form is readonly, but the employee should be have to reset his own leave to draft to modify it and re-submit it.
2016-09-20 12:01:53 +02:00
Yannick Tivisse 7fa2691175 [IMP] hr_*: Split the HR access rights by application
PURPOSE
=======

For each and every Hr application there should be one user category (One app = one category).

SPECIFICATION
=============

HR remains as it is : Employee, Officer, Manager

Each Application should have 2 access rights: User and Manager. Example for Recruitment:
- The user has access to the recruitment process
- The manager has access to the job position configuration

Each Application should grant the employee user access right (Namely the 'HR Officer')
2016-09-06 14:35:09 +02:00
Martin Trigaux 11812b0b9e [FIX] all: remove external ids fakely from base
Several modules defines records with the external ID `base.foo_bar` while it is
created inside this module (typically menus and groups).
While there is no technical reasons to do so but this may introduce issues:

- these records will not be deleted during uninstall
- if a language is loaded before the installation of the module, it won't be
  translated

The uninstallation will only remove the records with an external id linked to
this module (these would only be removed when removing base).

Installing a language before the module will drop the translations not linked
to an existing external id (as it can not be resolved).

This commit correct all the external ids tagged as from base or other incorrect
modules.
2016-09-02 16:14:26 +02:00
Ravi Gohil 46bc624479 [IMP] hr_holidays: a few code improvements
- added encoding to xml files
- replace search_read() with search() for _search_absent_employee()
- fixed setting first date of current month as default value for wizards
- reduce calls to <dict>.get()
2016-06-15 09:47:10 +02:00
Ravi Gohil 46ccb7036f [MIG] hr_holidays : migration to new api 2016-06-07 16:34:54 +02:00
Ravi Gohil ea2e476606 [MOV] hr_holidays: reorganize module directory
Also,
- removed unused hr_bel_holidays_2008.xml file
- removed unused action with xml_id 'act_hr_employee_holiday_request_approved' from hr_holidays_views.xml
2016-06-07 16:34:54 +02:00
Mohammed Shekha 783f246bde [IMP] hr_holidays: user reads only own leaves
In order to avoid all users being able to see leaves from everyone
the record rule is updated so that users see only their own leaves.

Code computing leave on employee record now uses super user to compute
it to ensure the current status of an employee is visible to other
employees.

Dashboard menus is now restricted to group hr_manager.
2016-03-04 14:57:48 +01:00
Bhavik Bagadiya d5ded74137 [IMP] hr_holidays: usability improvements
- New calendar dashboard with the leaves of every employee
- New "Leaves to Approve" menu with to-approve department leaves
- Renamed and reorder menus

Odoo Task 12913
Closes #7292
2015-09-07 18:28:09 +02:00
Christophe Simonis b67eb530b0 [FIX] hr_holidays: remove now invalid xml attribute "model" (introduced by last forward-port) 2014-08-28 17:17:10 +02:00
Christophe Simonis ada9724655 [MERGE] forward port of branch 7.0 up to 3509e15 2014-08-28 16:12:55 +02:00
Denis Ledoux 9b3f3fecfe [FIX] hr_holidays: employees cannot approve their holidays
Nor modify once approved

It wasn't possible for employees to approve their holidays themself, thanks to the GUI, but this was possible through xmlrpc calls, or when altering the html directly in the browser.
Besides, this was also possible to edit the holiday through the same trick once the holiday validated
2014-08-25 14:51:03 +02:00
jke-openerp 46b0c7aa00 [REF] Rename model crm.meeting into calendar.event
Remove 2 unsused field from calendar.event model (dir,sequence)

bzr revid: jke@openerp.com-20140115093805-1g1j1oymyxsb6kgh
2014-01-15 10:38:05 +01:00
jke-openerp eeb4e9629f [TYPO] Replace base_calendar to calendar in csv security
bzr revid: jke@openerp.com-20131219160620-kcjrqv0uald99qqe
2013-12-19 17:06:20 +01:00