global $user;
- // Step 1.
- // A client must have view_client_timesheets and
- // aser must be assigned to one of client projects.
- if ($user->isClient()) {
- if (!$user->can('view_client_timesheets'))
- return false;
- $valid_users = ttGroupHelper::getUsersForClient($user->client_id);
- $v = 2;
- }
-
- return true;
+ // TODO: we are currently re-designing timesheets.
+ // Clients are not supposed to view them at all.
+ // And the post will change on_behalf user, to keep things consistent.
+ return false;
}
// getReportOptions prepares $options array to be used with ttReportHelper
$sql = "select u.id, u.name, u.email".
" from tt_users u".
" left join tt_roles r on (r.id = u.role_id)".
- " where u.status = 1 and u.email is not null".
+ " where u.status = 1 and u.email is not null and u.group_id = $group_id and u.org_id = $org_id".
" and (r.rights like '%approve_all_timesheets%' or (r.rank > $rank and r.rights like '%approve_timesheets%'))";
$res = $mdb2->query($sql);
if (!is_a($res, 'PEAR_Error')) {
return true;
}
+
+ // approveTimesheet marks a timesheet as approved and sends an email to submitter.
+ static function approveTimesheet($fields) {
+ global $user;
+ $mdb2 = getConnection();
+
+ $group_id = $user->getGroup();
+ $org_id = $user->org_id;
+
+ // First, mark a timesheet as approved.
+ // Even if mail part below does not work, this will get us a functioning workflow
+ // (without email notifications).
+ $timesheet_id = $fields['timesheet_id'];
+ $manager_comment = $fields['comment'];
+
+ $sql = "update tt_timesheets set approval_status = 1, manager_comment = ".$mdb2->quote($manager_comment).
+ " where id = $timesheet_id and submit_status = 1 and group_id = $group_id and org_id = $org_id";
+ $affected = $mdb2->exec($sql);
+ if (is_a($affected, 'PEAR_Error')) return false;
+
+ // TODO: send email to submitter here...
+ return true;
+ }
+
+ // disapproveTimesheet marks a timesheet as approved and sends an email to submitter.
+ static function disapproveTimesheet($fields) {
+ global $user;
+ $mdb2 = getConnection();
+
+ $group_id = $user->getGroup();
+ $org_id = $user->org_id;
+
+ // First, mark a timesheet as disapproved.
+ // Even if mail part below does not work, this will get us a functioning workflow
+ // (without email notifications).
+ $timesheet_id = $fields['timesheet_id'];
+ $manager_comment = $fields['comment'];
+
+ $sql = "update tt_timesheets set approval_status = 0, manager_comment = ".$mdb2->quote($manager_comment).
+ " where id = $timesheet_id and submit_status = 1 and group_id = $group_id and org_id = $org_id";
+ $affected = $mdb2->exec($sql);
+ if (is_a($affected, 'PEAR_Error')) return false;
+
+ // TODO: send email to submitter here...
+ return true;
+ }
}