added project start and end date (#1303)
* added sortable js library * activity in invoice is optional * added javascript widget for paginated boxes * fix activity dropdown for globals only * added timesheet service to reduce code duplication * use repository to query for teams in dropdowns * added project validator * validate project start and end against timesheet * include begin and end in dynamic form requests for projects * added timezone and language option to import flag, improve timesheet import speed * deactivate cross-timezone filter * add virtual fields to field order list * composer update * added param to ignore dates * position loader icon fixed - fixes #1330 * permission problem when creating a new project - fixes #1340 * remove dev dependencies webserver and thanks bundle * stop information leak (begin and end date) in duration mode - fixes #1307 * unify timesheet edit dialog for user and admins * fix security issue, own rates exposed to unauthorized users in multi-update dialog
This commit is contained in:
@@ -61,6 +61,25 @@ class TeamRepository extends EntityRepository
|
||||
$entityManager->flush();
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns a query builder that is used for TeamType and your own 'query_builder' option.
|
||||
*
|
||||
* @param TeamQuery $query
|
||||
* @return QueryBuilder
|
||||
*/
|
||||
public function getQueryBuilderForFormType(TeamQuery $query): QueryBuilder
|
||||
{
|
||||
$qb = $this->getEntityManager()->createQueryBuilder();
|
||||
|
||||
$qb->select('t')
|
||||
->from(Team::class, 't')
|
||||
->orderBy('t.name', 'ASC');
|
||||
|
||||
$this->addPermissionCriteria($qb, $query->getCurrentUser(), $query->getTeams());
|
||||
|
||||
return $qb;
|
||||
}
|
||||
|
||||
public function getPagerfantaForQuery(TeamQuery $query): Pagerfanta
|
||||
{
|
||||
$paginator = new Pagerfanta($this->getPaginatorForQuery($query));
|
||||
@@ -134,6 +153,11 @@ class TeamRepository extends EntityRepository
|
||||
return $qb;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param QueryBuilder $qb
|
||||
* @param User|null $user
|
||||
* @param Team[] $teams
|
||||
*/
|
||||
private function addPermissionCriteria(QueryBuilder $qb, ?User $user = null, array $teams = [])
|
||||
{
|
||||
// make sure that all queries without a user see all user
|
||||
@@ -146,10 +170,21 @@ class TeamRepository extends EntityRepository
|
||||
return;
|
||||
}
|
||||
|
||||
$or = $qb->expr()->orX();
|
||||
|
||||
if (null !== $user) {
|
||||
$qb
|
||||
->andWhere('t.teamlead = :id')
|
||||
->setParameter('id', $user);
|
||||
$or->add($qb->expr()->eq('t.teamlead', ':id'));
|
||||
$qb->setParameter('id', $user);
|
||||
}
|
||||
|
||||
if (!empty($teams)) {
|
||||
$ids = [];
|
||||
foreach ($teams as $team) {
|
||||
$ids[] = $team->getId();
|
||||
}
|
||||
$or->add($qb->expr()->in('t.id', $ids));
|
||||
}
|
||||
|
||||
$qb->andWhere($or);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user