Release 2.14 (#4710)
- show "link has expired message" in password reset screen - added date objects as hydrator variables - for custom date formats in invoice templates - show meta-fields with null values (e.g. booleans with `false` where hidden) - fix permission check: allow to remove `view_own_timesheet` but still record times - prevent error 500 if customer country is empty - fix API 500 error if project does not exist when creating new timesheet - fix tags are not created in remote-search mode - do not check "export items" by default - fix daterange query, if user an request locale are different - added logging for invalid SAML responses (see various discussions)
This commit is contained in:
@@ -27,8 +27,15 @@ use Symfony\Component\HttpFoundation\Response;
|
||||
use Symfony\Component\Routing\Annotation\Route;
|
||||
use Symfony\Component\Security\Http\Attribute\IsGranted;
|
||||
|
||||
/**
|
||||
* No permission check on controller level, only for single routes.
|
||||
*
|
||||
* There was "view_other_timesheet" here once, but it is a bug.
|
||||
* Some companies (rarely, but existing) want their employees to enter time, but not to see it afterward.
|
||||
*
|
||||
* It is legit to only own "create_other_timesheet" without "view_other_timesheet".
|
||||
*/
|
||||
#[Route(path: '/team/timesheet')]
|
||||
#[IsGranted('view_other_timesheet')]
|
||||
final class TimesheetTeamController extends TimesheetAbstractController
|
||||
{
|
||||
#[Route(path: '/', defaults: ['page' => 1], name: 'admin_timesheet', methods: ['GET'])]
|
||||
|
||||
Reference in New Issue
Block a user