Release 1.6.2 (#1289)

* include user teams in user entity
* prevent unauthorized access via API
* improve teamlead permission handling in team timesheets
* add team data to user entity
* add security tests
* highlight menu for invoice template copy
* unified handling of invoice data across all templates
* access to the current users data in invoice templates
* permission improvement in invoice form
* allow to skip record rows
* allow to add new invoice locations without overwriting the global ones
* allow to order user preferences
* change permission for normal users with access to view_other_timesheets
* properly validate invoice template field length
* allow to replace multiple variables in cell values text
* upgraded office invoice template
* doctrine deprecation fix
* upgrade phpoffice/phpword
* fix future begin check for default rounding rules
* dashboard widget counter: respect visibility and teams - fixes #1161
* fix future begin check for default rounding rules
* added new events for pre and post invoice rendering
* fix permission issue for users without team seeing all records
* prevent error in spreadsheet renderer for empty invoices
This commit is contained in:
Kevin Papst
2019-12-02 10:57:03 +01:00
committed by GitHub
parent 47414cfd0e
commit 984c852ab6
78 changed files with 1279 additions and 625 deletions

View File

@@ -402,7 +402,7 @@ abstract class TimesheetAbstractController extends AbstractController
'action' => $this->generateUrl($this->getMultiUpdateRoute(), []),
'method' => 'POST',
'include_exported' => $this->isGranted($this->getPermissionEditExport()),
'include_user' => $this->includeUserInForms(),
'include_user' => $this->includeUserInForms('multi'),
]);
}
@@ -426,7 +426,7 @@ abstract class TimesheetAbstractController extends AbstractController
'action' => $this->generateUrl($this->getCreateRoute()),
'include_rate' => $this->isGranted('edit_rate', $entry),
'include_exported' => $this->isGranted('edit_export', $entry),
'include_user' => $this->includeUserInForms(),
'include_user' => $this->includeUserInForms('create'),
'allow_begin_datetime' => $mode->canEditBegin(),
'allow_end_datetime' => $mode->canEditEnd(),
'allow_duration' => $mode->canEditDuration(),
@@ -450,7 +450,7 @@ abstract class TimesheetAbstractController extends AbstractController
]),
'include_rate' => $this->isGranted('edit_rate', $entry),
'include_exported' => $this->isGranted('edit_export', $entry),
'include_user' => $this->includeUserInForms(),
'include_user' => $this->includeUserInForms('edit'),
'allow_begin_datetime' => $mode->canEditBegin(),
'allow_end_datetime' => $mode->canEditEnd(),
'allow_duration' => $mode->canEditDuration(),
@@ -469,7 +469,7 @@ abstract class TimesheetAbstractController extends AbstractController
'page' => $query->getPage(),
]),
'method' => 'GET',
'include_user' => $this->includeUserInForms(),
'include_user' => $this->includeUserInForms('toolbar'),
]);
}
@@ -493,7 +493,7 @@ abstract class TimesheetAbstractController extends AbstractController
return (bool) $this->getUser()->getPreferenceValue('timesheet.daily_stats', false);
}
protected function includeUserInForms(): bool
protected function includeUserInForms(string $formName): bool
{
return false;
}