Release 1.6.2 (#1289)

* include user teams in user entity
* prevent unauthorized access via API
* improve teamlead permission handling in team timesheets
* add team data to user entity
* add security tests
* highlight menu for invoice template copy
* unified handling of invoice data across all templates
* access to the current users data in invoice templates
* permission improvement in invoice form
* allow to skip record rows
* allow to add new invoice locations without overwriting the global ones
* allow to order user preferences
* change permission for normal users with access to view_other_timesheets
* properly validate invoice template field length
* allow to replace multiple variables in cell values text
* upgraded office invoice template
* doctrine deprecation fix
* upgrade phpoffice/phpword
* fix future begin check for default rounding rules
* dashboard widget counter: respect visibility and teams - fixes #1161
* fix future begin check for default rounding rules
* added new events for pre and post invoice rendering
* fix permission issue for users without team seeing all records
* prevent error in spreadsheet renderer for empty invoices
This commit is contained in:
Kevin Papst
2019-12-02 10:57:03 +01:00
committed by GitHub
parent 47414cfd0e
commit 984c852ab6
78 changed files with 1279 additions and 625 deletions

View File

@@ -24,6 +24,8 @@ use Symfony\Component\HttpFoundation\Response;
/**
* @RouteResource("Team")
*
* @Security("is_granted('IS_AUTHENTICATED_REMEMBERED')")
*/
class TeamController extends BaseApiController
{
@@ -78,6 +80,8 @@ class TeamController extends BaseApiController
* @SWG\Schema(ref="#/definitions/TeamEntity"),
* )
*
* @Security("is_granted('view_team')")
*
* @ApiSecurity(name="apiUser")
* @ApiSecurity(name="apiToken")
*/
@@ -90,7 +94,7 @@ class TeamController extends BaseApiController
}
$view = new View($data, 200);
$view->getContext()->setGroups(['Default', 'Entity', 'Team']);
$view->getContext()->setGroups(['Default', 'Entity', 'Team', 'Team_Entity']);
return $this->viewHandler->handle($view);
}