Release 1.6.2 (#1289)

* include user teams in user entity
* prevent unauthorized access via API
* improve teamlead permission handling in team timesheets
* add team data to user entity
* add security tests
* highlight menu for invoice template copy
* unified handling of invoice data across all templates
* access to the current users data in invoice templates
* permission improvement in invoice form
* allow to skip record rows
* allow to add new invoice locations without overwriting the global ones
* allow to order user preferences
* change permission for normal users with access to view_other_timesheets
* properly validate invoice template field length
* allow to replace multiple variables in cell values text
* upgraded office invoice template
* doctrine deprecation fix
* upgrade phpoffice/phpword
* fix future begin check for default rounding rules
* dashboard widget counter: respect visibility and teams - fixes #1161
* fix future begin check for default rounding rules
* added new events for pre and post invoice rendering
* fix permission issue for users without team seeing all records
* prevent error in spreadsheet renderer for empty invoices
This commit is contained in:
Kevin Papst
2019-12-02 10:57:03 +01:00
committed by GitHub
parent 47414cfd0e
commit 984c852ab6
78 changed files with 1279 additions and 625 deletions

View File

@@ -10,8 +10,11 @@
namespace App\Controller;
use App\Entity\InvoiceTemplate;
use App\Event\InvoicePostRenderEvent;
use App\Event\InvoicePreRenderEvent;
use App\Form\InvoiceTemplateForm;
use App\Form\Toolbar\InvoiceToolbarForm;
use App\Invoice\InvoiceFormatter;
use App\Invoice\InvoiceItemInterface;
use App\Invoice\InvoiceModel;
use App\Invoice\ServiceInvoice;
@@ -25,6 +28,7 @@ use Symfony\Component\Form\SubmitButton;
use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\Routing\Annotation\Route;
use Symfony\Contracts\EventDispatcher\EventDispatcherInterface;
/**
* Controller used to create invoices and manage invoice templates.
@@ -32,26 +36,36 @@ use Symfony\Component\Routing\Annotation\Route;
* @Route(path="/invoice")
* @Security("is_granted('view_invoice')")
*/
class InvoiceController extends AbstractController
final class InvoiceController extends AbstractController
{
/**
* @var ServiceInvoice
*/
protected $service;
private $service;
/**
* @var InvoiceTemplateRepository
*/
protected $invoiceRepository;
private $invoiceRepository;
/**
* @var UserDateTimeFactory
*/
protected $dateTimeFactory;
private $dateTimeFactory;
/**
* @var InvoiceFormatter
*/
private $formatter;
/**
* @var EventDispatcherInterface
*/
private $dispatcher;
public function __construct(ServiceInvoice $service, InvoiceTemplateRepository $invoice, UserDateTimeFactory $dateTimeFactory)
public function __construct(ServiceInvoice $service, InvoiceTemplateRepository $invoice, UserDateTimeFactory $dateTimeFactory, InvoiceFormatter $formatter, EventDispatcherInterface $dispatcher)
{
$this->service = $service;
$this->invoiceRepository = $invoice;
$this->dateTimeFactory = $dateTimeFactory;
$this->formatter = $formatter;
$this->dispatcher = $dispatcher;
}
/**
@@ -115,8 +129,14 @@ class InvoiceController extends AbstractController
$query->setEnd($end);
$query->setExported(InvoiceQuery::STATE_NOT_EXPORTED);
$query->setState(InvoiceQuery::STATE_STOPPED);
// limit access to data from teams
$query->setCurrentUser($this->getUser());
if (!$this->isGranted('view_other_timesheet')) {
// limit access to own data
$query->setUser($this->getUser());
}
return $query;
}
@@ -135,11 +155,15 @@ class InvoiceController extends AbstractController
foreach ($this->service->getRenderer() as $renderer) {
if ($renderer->supports($document)) {
$this->dispatcher->dispatch(new InvoicePreRenderEvent($model, $document, $renderer));
$response = $renderer->render($document, $model);
if ($query->isMarkAsExported()) {
$this->markEntriesAsExported($entries);
}
$this->dispatcher->dispatch(new InvoicePostRenderEvent($model, $document, $renderer, $response));
return $response;
}
}
@@ -216,9 +240,10 @@ class InvoiceController extends AbstractController
*/
protected function prepareModel(InvoiceQuery $query): InvoiceModel
{
$model = new InvoiceModel();
$model = new InvoiceModel($this->formatter);
$model
->setQuery($query)
->setUser($this->getUser())
->setCustomer($query->getCustomer())
;
@@ -340,6 +365,7 @@ class InvoiceController extends AbstractController
return $this->createForm(InvoiceToolbarForm::class, $query, [
'action' => $this->generateUrl('invoice', []),
'method' => $method,
'include_user' => $this->isGranted('view_other_timesheet'),
'attr' => [
'id' => 'invoice-print-form'
],