- if ($form->{vendor_id}) {
- $where .= " AND a.vendor_id = ?";
- push(@values, $form->{vendor_id});
- } elsif ($form->{vendor}) {
+ # Permissions:
+ # - Always return invoices & AP transactions for projects the employee has "view invoices" permissions for, no matter what the other rules say.
+ # - Exclude AP transactions if no permissions for them exist.
+ # - Limit to own invoices unless may edit all invoices.
+ # - If may edit all, allow filtering by employee.
+ my (@permission_where, @permission_values);
+
+ if ($::auth->assert('vendor_invoice_edit', 1)) {
+ if (!$::auth->assert('show_ap_transactions', 1)) {
+ push @permission_where, "NOT invoice = 'f'"; # remove ap transactions from Purchase -> Reports -> Invoices
+ }
+
+ if (!$::auth->assert('purchase_all_edit', 1)) {
+ # only show own invoices
+ push @permission_where, "a.employee_id = ?";
+ push @permission_values, SL::DB::Manager::Employee->current->id;
+
+ } else {
+ if ($form->{employee_id}) {
+ push @permission_where, "a.employee_id = ?";
+ push @permission_values, conv_i($form->{employee_id});
+ }
+ }
+ }
+
+ if (@permission_where || !$::auth->assert('vendor_invoice_edit', 1)) {
+ my $permission_where_str = @permission_where ? "OR (" . join(" AND ", map { "($_)" } @permission_where) . ")" : "";
+ $where .= qq|
+ AND ( (a.globalproject_id IN (
+ SELECT epi.project_id
+ FROM employee_project_invoices epi
+ WHERE epi.employee_id = ?))
+ $permission_where_str)
+ |;
+ push @values, SL::DB::Manager::Employee->current->id, @permission_values;
+ }
+
+ if ($form->{vendor}) {