Commit 094df7a0 authored by Stephane Bouvry's avatar Stephane Bouvry
Browse files

Requète de mise à jour des affectations sans objet + patch index des personnes ajoutées

parent 8b5c1ada
Loading
Loading
Loading
Loading
+29 −0
Changes for databases_maintenance/maintenance.sql: 29 added lines, 0 removed lines.
Original line number Diff line number Diff line

-- ---------------------------------------------------------------------------
-- BUG : Mauvaise affectation des ORGANISATIONS/PERSONNES aux ACTIVITÉS
-- ---------------------------------------------------------------------------


-- ---------------------------------------------------------------------------
-- PERSONNES <> ACTIVITÉS

-- Affichage des roles problématiques
SELECT * FROM activityperson
  WHERE roleobj_id IS NULL AND role != '';

-- MAJ des Rôles
UPDATE activityperson a SET roleobj_id = (SELECT r.id FROM user_role r WHERE r.role_id = a.role)
  WHERE roleobj_id IS NULL AND a.role != '';

-- ---------------------------------------------------------------------------
-- ORGANIZATIONS <> ACTIVITÉS

-- Afficher les affectations problématiques
SELECT * FROM activityorganization
  WHERE roleobj_id IS NULL AND role != '';

-- Mise à jour si possible
UPDATE activityorganization a SET roleobj_id = (SELECT r.id FROM organizationrole r WHERE r.label = a.role)
  WHERE roleobj_id IS NULL AND a.role != '';
------------------------------------------------------------------------------------------------------------------------
+1 −0
Changes for module/Oscar/src/Oscar/Controller/OrganizationController.php: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -379,6 +379,7 @@ class OrganizationController extends AbstractOscarController
            if( $form->isValid() ){
                $this->getEntityManager()->persist($entity);
                $this->getEntityManager()->flush($entity);
                $this->getOrganizationService()->getSearchEngineStrategy()->add($entity);
                $this->redirect()->toRoute('organization/show', ['id'=>$entity->getId()]);
            }
        }

qq

deleted100644 → 0
+0 −87
Changes for qq: 0 added lines, 87 removed lines.
Original line number Diff line number Diff line
diff --git a/module/Oscar/src/Oscar/Controller/TimesheetController.php b/module/Oscar/src/Oscar/Controller/TimesheetController.php
index e5107a28..4c841d3e 100644
--- a/module/Oscar/src/Oscar/Controller/TimesheetController.php
+++ b/module/Oscar/src/Oscar/Controller/TimesheetController.php
@@ -491,6 +491,18 @@ class TimesheetController extends AbstractOscarController
         ];
     }
 
+    /**
+     * Centralisation de la consultation des feuilles de temps d'une personne / activité
+     * Selon les critères envoyés.
+     *
+     * @return array|JsonModel
+     * @throws \Doctrine\ORM\ORMException
+     * @throws \Doctrine\ORM\OptimisticLockException
+     * @throws \Doctrine\ORM\TransactionRequiredException
+     * @throws \PHPExcel_Exception
+     * @throws \PHPExcel_Reader_Exception
+     * @throws \PHPExcel_Writer_Exception
+     */
     public function synthesisAllAction(){
 
         // Données reçues
@@ -500,6 +512,7 @@ class TimesheetController extends AbstractOscarController
         $period         = $this->params()->fromQuery('period', null);
         $error          = null;
 
+        ////////////////////////////////////////////////////////////////////////////////////////////////////////////////
         // Synthèse pour une activités
         if( $activity_id != null ){
 
@@ -512,6 +525,10 @@ class TimesheetController extends AbstractOscarController
                 return $this->getResponseInternalError(sprintf(_("Activité introuvable")));
             }
 
+            // Contrôle des droits d'accès
+            $this->getOscarUserContext()->check(Privileges::ACTIVITY_TIMESHEET_VIEW, $activity);
+
+            // Obtention des IDS des déclarants
             foreach ($activity->getDeclarers() as $person) {
                 $personsIds[] = $person->getId();
             }
@@ -519,21 +536,32 @@ class TimesheetController extends AbstractOscarController
             if( count($personsIds) == 0 ){
                 return $this->getResponseInternalError(sprintf(_("Il n'y a pas de déclarants dans cette activité")));
             }
-
-            $this->getLogger()->debug("Récupération de la synthèse pour $activity");
-
             $datas = $this->getTimesheetService()->getDatasDeclarersSynthesis($personsIds);
             $horslots = $this->getTimesheetService()->getOthersWP();
         }
+
+        ////////////////////////////////////////////////////////////////////////////////////////////////////////////////
         // Synthèse pour la personne
         elseif ( $person_id != null ){
+
             $person = $this->getPersonService()->getPerson($person_id);
+
             if( !$person ){
                 return $this->getResponseInternalError(_("La personne est introuvable"));
             }
+
+            // Contrôle des droits d'accès
+            $global = $this->getOscarUserContext()->hasPrivileges(Privileges::ACTIVITY_TIMESHEET_VIEW);
+            if( !$global ){
+                if( !in_array($this->getCurrentPerson(), $this->getPersonService()->getManagers($person)) ){
+                    return $this->getResponseUnauthorized("Vous n'avez pas les droits pour voir la feuille de temps de $person");
+                }
+            }
+
             if( !$period ){
                 return $this->getResponseBadRequest(_("Vous devez spécifier la période"));
             }
+
             $split = explode('-', $period);
             $periodOk = DateTimeUtils::getCodePeriod($split[0], $split[1]);
             $datas = $this->getTimesheetService()->getTimesheetDatasPersonPeriod($person, $period);
@@ -617,7 +645,7 @@ class TimesheetController extends AbstractOscarController
 
     public function syntheseActivityAction(){
 
-        echo "<pre>";
+        $this->getOscarUserContext()->check(Privileges::ACTIVITY_TIMESHEET_VIEW);
 
         $currentActivityId = $this->params()->fromRoute('id');
         $month = $this->params()->fromQuery('month', date('m'));