Release 1.6.2 (#1289)

* include user teams in user entity
* prevent unauthorized access via API
* improve teamlead permission handling in team timesheets
* add team data to user entity
* add security tests
* highlight menu for invoice template copy
* unified handling of invoice data across all templates
* access to the current users data in invoice templates
* permission improvement in invoice form
* allow to skip record rows
* allow to add new invoice locations without overwriting the global ones
* allow to order user preferences
* change permission for normal users with access to view_other_timesheets
* properly validate invoice template field length
* allow to replace multiple variables in cell values text
* upgraded office invoice template
* doctrine deprecation fix
* upgrade phpoffice/phpword
* fix future begin check for default rounding rules
* dashboard widget counter: respect visibility and teams - fixes #1161
* fix future begin check for default rounding rules
* added new events for pre and post invoice rendering
* fix permission issue for users without team seeing all records
* prevent error in spreadsheet renderer for empty invoices
This commit is contained in:
Kevin Papst
2019-12-02 10:57:03 +01:00
committed by GitHub
parent 47414cfd0e
commit 984c852ab6
78 changed files with 1279 additions and 625 deletions

View File

@@ -16,7 +16,7 @@ use App\Entity\User;
*/
class ConfigurationControllerTest extends APIControllerBaseTest
{
public function testI18nIsSecure()
public function testIsSecure()
{
$this->assertUrlIsSecured('/api/config/i18n');
}

View File

@@ -20,6 +20,7 @@ class StatusControllerTest extends APIControllerBaseTest
public function testIsSecure()
{
$this->assertUrlIsSecured('/api/ping');
$this->assertUrlIsSecured('/api/version');
}
public function testPing()

View File

@@ -31,6 +31,11 @@ class TagControllerTest extends APIControllerBaseTest
$this->importFixture($em, $fixture);
}
public function testIsSecure()
{
$this->assertUrlIsSecured('/api/tags');
}
public function testGetCollection()
{
$client = $this->getClientForAuthenticatedUser(User::ROLE_USER);

View File

@@ -30,6 +30,8 @@ class TeamControllerTest extends APIControllerBaseTest
public function testIsSecure()
{
$this->assertUrlIsSecured('/api/teams');
$this->assertUrlIsSecuredForRole(User::ROLE_USER, '/api/teams');
$this->assertUrlIsSecuredForRole(User::ROLE_TEAMLEAD, '/api/teams');
}
public function testGetCollection()
@@ -56,7 +58,7 @@ class TeamControllerTest extends APIControllerBaseTest
public function testNotFound()
{
$this->assertEntityNotFound(User::ROLE_USER, '/api/teams/3');
$this->assertEntityNotFound(User::ROLE_ADMIN, '/api/teams/3');
}
public function testDeleteActionWithUnknownTeam()
@@ -80,7 +82,7 @@ class TeamControllerTest extends APIControllerBaseTest
$this->assertEquals(Response::HTTP_NO_CONTENT, $client->getResponse()->getStatusCode());
$this->assertEmpty($client->getResponse()->getContent());
$this->assertEntityNotFound(User::ROLE_USER, '/api/teams/' . $id);
$this->assertEntityNotFound(User::ROLE_ADMIN, '/api/teams/' . $id);
}
protected function assertStructure(array $result, $full = true)
@@ -90,7 +92,9 @@ class TeamControllerTest extends APIControllerBaseTest
];
if ($full) {
$expectedKeys = array_merge($expectedKeys, []);
$expectedKeys = array_merge($expectedKeys, [
'teamlead', 'users'
]);
}
$actual = array_keys($result);

View File

@@ -19,6 +19,8 @@ class UserControllerTest extends APIControllerBaseTest
public function testIsSecure()
{
$this->assertUrlIsSecured('/api/users');
$this->assertUrlIsSecuredForRole(User::ROLE_USER, '/api/users');
$this->assertUrlIsSecuredForRole(User::ROLE_TEAMLEAD, '/api/users');
$this->assertUrlIsSecuredForRole(User::ROLE_ADMIN, '/api/users');
}
@@ -118,7 +120,7 @@ class UserControllerTest extends APIControllerBaseTest
if ($full) {
$expectedKeys = array_merge(
$expectedKeys,
['title', 'avatar', 'roles', 'language', 'timezone']
['title', 'avatar', 'teams', 'roles', 'language', 'timezone']
);
}