* include user teams in user entity * prevent unauthorized access via API * improve teamlead permission handling in team timesheets * add team data to user entity * add security tests * highlight menu for invoice template copy * unified handling of invoice data across all templates * access to the current users data in invoice templates * permission improvement in invoice form * allow to skip record rows * allow to add new invoice locations without overwriting the global ones * allow to order user preferences * change permission for normal users with access to view_other_timesheets * properly validate invoice template field length * allow to replace multiple variables in cell values text * upgraded office invoice template * doctrine deprecation fix * upgrade phpoffice/phpword * fix future begin check for default rounding rules * dashboard widget counter: respect visibility and teams - fixes #1161 * fix future begin check for default rounding rules * added new events for pre and post invoice rendering * fix permission issue for users without team seeing all records * prevent error in spreadsheet renderer for empty invoices
155 lines
4.6 KiB
PHP
155 lines
4.6 KiB
PHP
<?php
|
|
|
|
/*
|
|
* This file is part of the Kimai time-tracking app.
|
|
*
|
|
* For the full copyright and license information, please view the LICENSE
|
|
* file that was distributed with this source code.
|
|
*/
|
|
|
|
namespace App\EventSubscriber;
|
|
|
|
use App\Entity\User;
|
|
use App\Event\DashboardEvent;
|
|
use App\Repository\ActivityRepository;
|
|
use App\Repository\CustomerRepository;
|
|
use App\Repository\ProjectRepository;
|
|
use App\Repository\Query\ActivityQuery;
|
|
use App\Repository\Query\CustomerQuery;
|
|
use App\Repository\Query\ProjectQuery;
|
|
use App\Repository\Query\UserQuery;
|
|
use App\Repository\UserRepository;
|
|
use App\Widget\Type\CompoundRow;
|
|
use App\Widget\Type\More;
|
|
use Symfony\Component\EventDispatcher\EventSubscriberInterface;
|
|
use Symfony\Component\Security\Core\Authorization\AuthorizationCheckerInterface;
|
|
|
|
/**
|
|
* Used to add Dashboard widgets for users with ROLE_ADMIN.
|
|
*/
|
|
class DashboardSubscriber implements EventSubscriberInterface
|
|
{
|
|
/**
|
|
* @var AuthorizationCheckerInterface
|
|
*/
|
|
protected $security;
|
|
/**
|
|
* @var UserRepository
|
|
*/
|
|
protected $user;
|
|
/**
|
|
* @var ActivityRepository
|
|
*/
|
|
protected $activity;
|
|
/**
|
|
* @var ProjectRepository
|
|
*/
|
|
protected $project;
|
|
/**
|
|
* @var CustomerRepository
|
|
*/
|
|
protected $customer;
|
|
|
|
/**
|
|
* @param AuthorizationCheckerInterface $security
|
|
* @param UserRepository $user
|
|
* @param ActivityRepository $activity
|
|
* @param ProjectRepository $project
|
|
* @param CustomerRepository $customer
|
|
*/
|
|
public function __construct(
|
|
AuthorizationCheckerInterface $security,
|
|
UserRepository $user,
|
|
ActivityRepository $activity,
|
|
ProjectRepository $project,
|
|
CustomerRepository $customer
|
|
) {
|
|
$this->security = $security;
|
|
$this->user = $user;
|
|
$this->activity = $activity;
|
|
$this->project = $project;
|
|
$this->customer = $customer;
|
|
}
|
|
|
|
/**
|
|
* @return array
|
|
*/
|
|
public static function getSubscribedEvents(): array
|
|
{
|
|
return [
|
|
DashboardEvent::class => ['onDashboardEvent', 100],
|
|
];
|
|
}
|
|
|
|
/**
|
|
* @param DashboardEvent $event
|
|
*/
|
|
public function onDashboardEvent(DashboardEvent $event)
|
|
{
|
|
$user = $event->getUser();
|
|
$section = new CompoundRow();
|
|
$section->setTitle('');
|
|
$section->setOrder(100);
|
|
|
|
if ($this->security->isGranted('view_user')) {
|
|
$section->addWidget(
|
|
(new More())
|
|
->setId('userTotal')
|
|
->setTitle('stats.userTotal')
|
|
->setData($this->user->countUsersForQuery((new UserQuery())->setCurrentUser($user)))
|
|
->setOptions([
|
|
'route' => 'admin_user',
|
|
'icon' => 'user',
|
|
'color' => 'primary',
|
|
])
|
|
);
|
|
}
|
|
|
|
if ($this->security->isGranted('view_customer')) {
|
|
$section->addWidget(
|
|
(new More())
|
|
->setId('customerTotal')
|
|
->setTitle('stats.customerTotal')
|
|
->setData($this->customer->countCustomersForQuery((new CustomerQuery())->setCurrentUser($user)))
|
|
->setOptions([
|
|
'route' => 'admin_customer',
|
|
'icon' => 'customer',
|
|
'color' => 'primary',
|
|
])
|
|
);
|
|
}
|
|
|
|
if ($this->security->isGranted('view_project')) {
|
|
$section->addWidget(
|
|
(new More())
|
|
->setId('projectTotal')
|
|
->setTitle('stats.projectTotal')
|
|
->setData($this->project->countProjectsForQuery((new ProjectQuery())->setCurrentUser($user)))
|
|
->setOptions([
|
|
'route' => 'admin_project',
|
|
'icon' => 'project',
|
|
'color' => 'primary',
|
|
])
|
|
);
|
|
}
|
|
|
|
if ($this->security->isGranted('view_activity')) {
|
|
$section->addWidget(
|
|
(new More())
|
|
->setId('activityTotal')
|
|
->setTitle('stats.activityTotal')
|
|
->setData($this->activity->countActivitiesForQuery((new ActivityQuery())->setCurrentUser($user)))
|
|
->setOptions([
|
|
'route' => 'admin_activity',
|
|
'icon' => 'activity',
|
|
'color' => 'primary',
|
|
])
|
|
);
|
|
}
|
|
|
|
if (count($section->getWidgets()) > 0) {
|
|
$event->addSection($section);
|
|
}
|
|
}
|
|
}
|