Zeiterfassung: Recht berücksichtigen, Einträge von anderen (nicht) zu sehen
authorBernd Bleßmann <bernd@kivitendo-premium.de>
Mon, 28 Dec 2020 14:33:33 +0000 (15:33 +0100)
committerBernd Bleßmann <bernd@kivitendo-premium.de>
Wed, 5 May 2021 15:25:02 +0000 (17:25 +0200)
SL/Controller/TimeRecording.pm
templates/webpages/time_recording/_filter.html

index 0a171a6..9ed3c72 100644 (file)
@@ -18,7 +18,7 @@ use SL::ReportGenerator;
 use Rose::Object::MakeMethods::Generic
 (
 # scalar                  => [ qw() ],
- 'scalar --get_set_init' => [ qw(time_recording models all_time_recording_types all_employees) ],
+ 'scalar --get_set_init' => [ qw(time_recording models all_time_recording_types all_employees can_view_all) ],
 );
 
 
@@ -126,11 +126,21 @@ sub init_time_recording {
   return $time_recording;
 }
 
+sub init_can_view_all {
+  $::auth->assert('time_recording_show_all', 1) || $::auth->assert('time_recording_edit_all', 1)
+}
+
 sub init_models {
+  my ($self) = @_;
+
+  my @where;
+  push @where, (staff_member_id => SL::DB::Manager::Employee->current->id) if !$self->can_view_all;
+
   SL::Controller::Helper::GetModels->new(
     controller     => $_[0],
     sorted         => \%sort_columns,
     disable_plugin => 'paginated',
+    query          => \@where,
     with_objects   => [ 'customer', 'type', 'project', 'staff_member', 'employee' ],
   );
 }
index c94f00d..b47b55d 100644 (file)
@@ -26,6 +26,8 @@
     <th align="right">[% 'Customer Number' | $T8 %]</th>
     <td>[% L.input_tag('filter.customer.customernumber:substr::ilike', filter.customer.customernumber_substr__ilike, size = 20) %]</td>
   </tr>
+
+  [%- IF SELF.can_view_all -%]
   <tr>
    <th align="right">[% 'Mitarbeiter' | $T8 %]</th>
    <td>
@@ -37,6 +39,8 @@
                      style      => 'width: 200px') %]
    </td>
   </tr>
+  [%- END -%]
+
  </table>
 
 [% L.hidden_tag('sort_by', FORM.sort_by) %]