From 2278082a4d183fd15a62c7dbb9d08f8f9f763b53 Mon Sep 17 00:00:00 2001 From: Lance Edgar Date: Thu, 8 Dec 2022 20:51:07 -0600 Subject: [PATCH] Cleanup employees view per new supplements also add permission for "view employee secrets" (where applicable) --- tailbone/views/employees.py | 13 ++++++++++--- tailbone/views/master.py | 4 ++++ 2 files changed, 14 insertions(+), 3 deletions(-) diff --git a/tailbone/views/employees.py b/tailbone/views/employees.py index b45e78e7..f07d319a 100644 --- a/tailbone/views/employees.py +++ b/tailbone/views/employees.py @@ -154,10 +154,11 @@ class EmployeeView(MasterView): g.set_link('last_name') def query(self, session): - q = session.query(model.Employee).join(model.Person) + query = super(EmployeeView, self).query(session) + query = query.join(model.Person) if not self.has_perm('view_all'): - q = q.filter(model.Employee.status == self.enum.EMPLOYEE_STATUS_CURRENT) - return q + query = query.filter(model.Employee.status == self.enum.EMPLOYEE_STATUS_CURRENT) + return query def grid_render_username(self, employee, field): person = employee.person if employee else None @@ -327,6 +328,7 @@ class EmployeeView(MasterView): @classmethod def _employee_defaults(cls, config): permission_prefix = cls.get_permission_prefix() + model_title = cls.get_model_title() model_title_plural = cls.get_model_title_plural() # view *all* employees @@ -334,6 +336,11 @@ class EmployeeView(MasterView): '{}.view_all'.format(permission_prefix), "View *all* (not just current) {}".format(model_title_plural)) + # view employee "secrets" + config.add_tailbone_permission(permission_prefix, + '{}.view_secrets'.format(permission_prefix), + "View \"secrets\" for {} (e.g. login ID, passcode)".format(model_title)) + def defaults(config, **kwargs): base = globals() diff --git a/tailbone/views/master.py b/tailbone/views/master.py index 7e1925a2..b03ebcf8 100644 --- a/tailbone/views/master.py +++ b/tailbone/views/master.py @@ -5124,4 +5124,8 @@ class ViewSupplement(object): @classmethod def defaults(cls, config): + cls._defaults(config) + + @classmethod + def _defaults(cls, config): config.add_tailbone_view_supplement(cls.route_prefix, cls)