Release 1.6.2 (#1289)

* include user teams in user entity
* prevent unauthorized access via API
* improve teamlead permission handling in team timesheets
* add team data to user entity
* add security tests
* highlight menu for invoice template copy
* unified handling of invoice data across all templates
* access to the current users data in invoice templates
* permission improvement in invoice form
* allow to skip record rows
* allow to add new invoice locations without overwriting the global ones
* allow to order user preferences
* change permission for normal users with access to view_other_timesheets
* properly validate invoice template field length
* allow to replace multiple variables in cell values text
* upgraded office invoice template
* doctrine deprecation fix
* upgrade phpoffice/phpword
* fix future begin check for default rounding rules
* dashboard widget counter: respect visibility and teams - fixes #1161
* fix future begin check for default rounding rules
* added new events for pre and post invoice rendering
* fix permission issue for users without team seeing all records
* prevent error in spreadsheet renderer for empty invoices
This commit is contained in:
Kevin Papst
2019-12-02 10:57:03 +01:00
committed by GitHub
parent 47414cfd0e
commit 984c852ab6
78 changed files with 1279 additions and 625 deletions

View File

@@ -14,6 +14,10 @@ use App\Event\DashboardEvent;
use App\Repository\ActivityRepository;
use App\Repository\CustomerRepository;
use App\Repository\ProjectRepository;
use App\Repository\Query\ActivityQuery;
use App\Repository\Query\CustomerQuery;
use App\Repository\Query\ProjectQuery;
use App\Repository\Query\UserQuery;
use App\Repository\UserRepository;
use App\Widget\Type\CompoundRow;
use App\Widget\Type\More;
@@ -82,8 +86,9 @@ class DashboardSubscriber implements EventSubscriberInterface
*/
public function onDashboardEvent(DashboardEvent $event)
{
$user = $event->getUser();
$section = new CompoundRow();
$section->setTitle('ROLE_ADMIN');
$section->setTitle('');
$section->setOrder(100);
if ($this->security->isGranted('view_user')) {
@@ -91,7 +96,7 @@ class DashboardSubscriber implements EventSubscriberInterface
(new More())
->setId('userTotal')
->setTitle('stats.userTotal')
->setData($this->user->countUser())
->setData($this->user->countUsersForQuery((new UserQuery())->setCurrentUser($user)))
->setOptions([
'route' => 'admin_user',
'icon' => 'user',
@@ -105,7 +110,7 @@ class DashboardSubscriber implements EventSubscriberInterface
(new More())
->setId('customerTotal')
->setTitle('stats.customerTotal')
->setData($this->customer->countCustomer())
->setData($this->customer->countCustomersForQuery((new CustomerQuery())->setCurrentUser($user)))
->setOptions([
'route' => 'admin_customer',
'icon' => 'customer',
@@ -119,7 +124,7 @@ class DashboardSubscriber implements EventSubscriberInterface
(new More())
->setId('projectTotal')
->setTitle('stats.projectTotal')
->setData($this->project->countProject())
->setData($this->project->countProjectsForQuery((new ProjectQuery())->setCurrentUser($user)))
->setOptions([
'route' => 'admin_project',
'icon' => 'project',
@@ -133,7 +138,7 @@ class DashboardSubscriber implements EventSubscriberInterface
(new More())
->setId('activityTotal')
->setTitle('stats.activityTotal')
->setData($this->activity->countActivity())
->setData($this->activity->countActivitiesForQuery((new ActivityQuery())->setCurrentUser($user)))
->setOptions([
'route' => 'admin_activity',
'icon' => 'activity',