mirror of
https://github.com/solidtime-io/solidtime.git
synced 2026-10-08 13:53:17 +01:00
Compare commits
5 Commits
feature/fi
...
feature/cl
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
194fa6cf49 | ||
|
|
349623d537 | ||
|
|
a9d016d773 | ||
|
|
2ebbbceefb | ||
|
|
e85058aefd |
@@ -679,6 +679,10 @@ class TimeEntryController extends Controller
|
||||
$timeEntry->member()->associate($newMember);
|
||||
$timeEntry->user()->associate($newMember->user);
|
||||
}
|
||||
// If project is changed, but task is not, we remove the old task from the time entry
|
||||
if ($request->has('project_id') && ! $request->has('task_id') && $oldTask !== null && $oldTask->project_id !== $project?->getKey()) {
|
||||
$timeEntry->task()->disassociate();
|
||||
}
|
||||
$timeEntry->description = $request->input('description', $timeEntry->description) ?? '';
|
||||
$timeEntry->setComputedAttributeValue('billable_rate');
|
||||
$timeEntry->save();
|
||||
@@ -790,7 +794,7 @@ class TimeEntryController extends Controller
|
||||
$timeEntry->user_id = $newMember->user_id;
|
||||
}
|
||||
// If project is changed, but task is not, we remove the old task from the time entry
|
||||
if ($oldProject !== null && $project !== null && $oldProject->isNot($project) && $task === null) {
|
||||
if ($request->has('changes.project_id') && ! $request->has('changes.task_id') && $oldTask !== null && $oldTask->project_id !== $project?->getKey()) {
|
||||
$timeEntry->task()->disassociate();
|
||||
}
|
||||
if ($overwriteClient) {
|
||||
|
||||
@@ -11,6 +11,7 @@ use App\Models\Client;
|
||||
use App\Models\Member;
|
||||
use App\Models\Organization;
|
||||
use App\Models\OrganizationInvitation;
|
||||
use App\Models\Passport\RefreshToken;
|
||||
use App\Models\Project;
|
||||
use App\Models\ProjectMember;
|
||||
use App\Models\Report;
|
||||
@@ -169,6 +170,10 @@ class DeletionService
|
||||
}
|
||||
}
|
||||
|
||||
// Refresh tokens are not linked to the user directly, so they need to be deleted via their access tokens.
|
||||
// Otherwise a still-valid refresh token could be used to issue a new access token for a deleted user,
|
||||
// which fails with a foreign key violation on oauth_access_tokens.user_id.
|
||||
RefreshToken::query()->whereIn('access_token_id', $user->accessTokens()->pluck('id'))->delete();
|
||||
$user->accessTokens()->delete();
|
||||
$user->authCodes()->delete();
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"Billing": {
|
||||
"repository": "solidtime-io/extension-billing",
|
||||
"ref": "v0.0.7"
|
||||
"ref": "v0.0.8"
|
||||
},
|
||||
"Services": {
|
||||
"repository": "solidtime-io/extension-services",
|
||||
|
||||
@@ -168,6 +168,10 @@ defineExpose({ submit, focusAfterStart });
|
||||
data-testid="time_entry_description"
|
||||
class="w-full rounded-l-lg py-4 sm:py-2.5 px-3.5 border-b border-b-card-background-separator @2xl:px-4 text-base text-text-primary bg-transparent border-none placeholder-text-secondary focus:ring-0 transition"
|
||||
type="text"
|
||||
autocomplete="off"
|
||||
data-1p-ignore
|
||||
data-lpignore="true"
|
||||
data-form-type="other"
|
||||
@keydown.enter="submit"
|
||||
@keydown.esc="showDropdown = false"
|
||||
@blur="updateTimeEntryDescription" />
|
||||
|
||||
@@ -170,6 +170,10 @@ function closeAndFocusInput() {
|
||||
: 'text-text-primary bg-card-background border-border-secondary border border-none'
|
||||
"
|
||||
type="text"
|
||||
autocomplete="off"
|
||||
data-1p-ignore
|
||||
data-lpignore="true"
|
||||
data-form-type="other"
|
||||
@focusin="openModalOnTab"
|
||||
@click="openModalOnClick"
|
||||
@keydown.exact.tab="focusNextElement"
|
||||
|
||||
@@ -19,7 +19,7 @@ export const useNotificationsStore = defineStore('notifications', () => {
|
||||
const showActionBlockedModal = ref(false);
|
||||
|
||||
function addNotification(type: NotificationType, title: string, message?: string) {
|
||||
const uuid = crypto.randomUUID();
|
||||
const uuid = Math.random().toString(36).substring(7);
|
||||
notifications.value.push({ title, message, type, uuid });
|
||||
|
||||
setTimeout(() => {
|
||||
|
||||
@@ -2780,6 +2780,90 @@ class TimeEntryEndpointTest extends ApiEndpointTestAbstract
|
||||
});
|
||||
}
|
||||
|
||||
public function test_update_endpoint_removes_task_if_project_is_changed_without_setting_a_new_task(): void
|
||||
{
|
||||
// Arrange
|
||||
$data = $this->createUserWithPermission([
|
||||
'time-entries:update:own',
|
||||
'projects:view:all',
|
||||
]);
|
||||
$project1 = Project::factory()->forOrganization($data->organization)->create();
|
||||
$project2 = Project::factory()->forOrganization($data->organization)->create();
|
||||
$task1 = Task::factory()->forProject($project1)->forOrganization($data->organization)->create();
|
||||
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project1)->forTask($task1)->forMember($data->member)->create();
|
||||
Passport::actingAs($data->user);
|
||||
|
||||
// Act
|
||||
$response = $this->putJson(route('api.v1.time-entries.update', [$data->organization->getKey(), $timeEntry->getKey()]), [
|
||||
'project_id' => $project2->getKey(),
|
||||
]);
|
||||
|
||||
// Assert
|
||||
$response->assertValid();
|
||||
$this->assertResponseCode($response, 200);
|
||||
$response->assertJsonPath('data.project_id', $project2->getKey());
|
||||
$response->assertJsonPath('data.task_id', null);
|
||||
$this->assertDatabaseHas(TimeEntry::class, [
|
||||
'id' => $timeEntry->getKey(),
|
||||
'project_id' => $project2->getKey(),
|
||||
'task_id' => null,
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_update_endpoint_removes_task_if_project_is_removed_without_removing_the_task(): void
|
||||
{
|
||||
// Arrange
|
||||
$data = $this->createUserWithPermission([
|
||||
'time-entries:update:own',
|
||||
'projects:view:all',
|
||||
]);
|
||||
$project = Project::factory()->forOrganization($data->organization)->create();
|
||||
$task = Task::factory()->forProject($project)->forOrganization($data->organization)->create();
|
||||
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project)->forTask($task)->forMember($data->member)->create();
|
||||
Passport::actingAs($data->user);
|
||||
|
||||
// Act
|
||||
$response = $this->putJson(route('api.v1.time-entries.update', [$data->organization->getKey(), $timeEntry->getKey()]), [
|
||||
'project_id' => null,
|
||||
]);
|
||||
|
||||
// Assert
|
||||
$response->assertValid();
|
||||
$this->assertResponseCode($response, 200);
|
||||
$this->assertDatabaseHas(TimeEntry::class, [
|
||||
'id' => $timeEntry->getKey(),
|
||||
'project_id' => null,
|
||||
'task_id' => null,
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_update_endpoint_keeps_task_if_project_is_set_to_the_project_of_the_task(): void
|
||||
{
|
||||
// Arrange
|
||||
$data = $this->createUserWithPermission([
|
||||
'time-entries:update:own',
|
||||
'projects:view:all',
|
||||
]);
|
||||
$project = Project::factory()->forOrganization($data->organization)->create();
|
||||
$task = Task::factory()->forProject($project)->forOrganization($data->organization)->create();
|
||||
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project)->forTask($task)->forMember($data->member)->create();
|
||||
Passport::actingAs($data->user);
|
||||
|
||||
// Act
|
||||
$response = $this->putJson(route('api.v1.time-entries.update', [$data->organization->getKey(), $timeEntry->getKey()]), [
|
||||
'project_id' => $project->getKey(),
|
||||
]);
|
||||
|
||||
// Assert
|
||||
$response->assertValid();
|
||||
$this->assertResponseCode($response, 200);
|
||||
$this->assertDatabaseHas(TimeEntry::class, [
|
||||
'id' => $timeEntry->getKey(),
|
||||
'project_id' => $project->getKey(),
|
||||
'task_id' => $task->getKey(),
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_update_endpoint_fails_if_employee_tries_to_update_time_entry_to_private_project_without_access(): void
|
||||
{
|
||||
// Arrange
|
||||
@@ -3807,6 +3891,44 @@ class TimeEntryEndpointTest extends ApiEndpointTestAbstract
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_update_multiple_removes_task_from_time_entries_if_project_is_removed_without_removing_the_task(): void
|
||||
{
|
||||
// Arrange
|
||||
$data = $this->createUserWithPermission([
|
||||
'time-entries:update:own',
|
||||
'projects:view:all',
|
||||
]);
|
||||
$project = Project::factory()->forOrganization($data->organization)->create();
|
||||
$task = Task::factory()->forProject($project)->forOrganization($data->organization)->create();
|
||||
$timeEntry = TimeEntry::factory()->forOrganization($data->organization)->forProject($project)->forTask($task)->forMember($data->member)->create();
|
||||
Passport::actingAs($data->user);
|
||||
|
||||
// Act
|
||||
$response = $this->patchJson(route('api.v1.time-entries.update-multiple', [$data->organization->getKey()]), [
|
||||
'ids' => [
|
||||
$timeEntry->getKey(),
|
||||
],
|
||||
'changes' => [
|
||||
'project_id' => null,
|
||||
],
|
||||
]);
|
||||
|
||||
// Assert
|
||||
$response->assertValid();
|
||||
$this->assertResponseCode($response, 200);
|
||||
$response->assertExactJson([
|
||||
'success' => [
|
||||
$timeEntry->getKey(),
|
||||
],
|
||||
'error' => [],
|
||||
]);
|
||||
$this->assertDatabaseHas(TimeEntry::class, [
|
||||
'id' => $timeEntry->getKey(),
|
||||
'project_id' => null,
|
||||
'task_id' => null,
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_update_multiple_updates_own_time_entries_and_fails_for_time_entries_of_other_users_and_and_other_organizations_with_own_time_entries_permission(): void
|
||||
{
|
||||
// Arrange
|
||||
|
||||
@@ -10,6 +10,9 @@ use App\Exceptions\Api\CanNotDeleteUserWhoIsOwnerOfOrganizationWithMultipleMembe
|
||||
use App\Models\Client;
|
||||
use App\Models\Member;
|
||||
use App\Models\Organization;
|
||||
use App\Models\Passport\Client as PassportClient;
|
||||
use App\Models\Passport\RefreshToken;
|
||||
use App\Models\Passport\Token;
|
||||
use App\Models\Project;
|
||||
use App\Models\ProjectMember;
|
||||
use App\Models\Report;
|
||||
@@ -23,6 +26,7 @@ use Illuminate\Support\Collection;
|
||||
use Illuminate\Support\Facades\Event;
|
||||
use Illuminate\Support\Facades\Log;
|
||||
use Illuminate\Support\Facades\Storage;
|
||||
use Illuminate\Support\Str;
|
||||
use PHPUnit\Framework\Attributes\CoversClass;
|
||||
use Tests\TestCaseWithDatabase;
|
||||
use TiMacDonald\Log\LogEntry;
|
||||
@@ -424,4 +428,45 @@ class DeletionServiceTest extends TestCaseWithDatabase
|
||||
'role' => Role::Placeholder->value,
|
||||
]);
|
||||
}
|
||||
|
||||
public function test_delete_user_deletes_access_tokens_and_their_refresh_tokens_but_does_not_delete_tokens_of_other_users(): void
|
||||
{
|
||||
// Arrange
|
||||
$user = User::factory()->create();
|
||||
$otherUser = User::factory()->create();
|
||||
$passportClient = PassportClient::factory()->create();
|
||||
|
||||
$userToken = Token::factory()->forUser($user)->forClient($passportClient)->create();
|
||||
$userRefreshToken = RefreshToken::query()->create([
|
||||
'id' => Str::random(100),
|
||||
'access_token_id' => $userToken->getKey(),
|
||||
'revoked' => false,
|
||||
'expires_at' => now()->addDays(30),
|
||||
]);
|
||||
|
||||
$otherUserToken = Token::factory()->forUser($otherUser)->forClient($passportClient)->create();
|
||||
$otherUserRefreshToken = RefreshToken::query()->create([
|
||||
'id' => Str::random(100),
|
||||
'access_token_id' => $otherUserToken->getKey(),
|
||||
'revoked' => false,
|
||||
'expires_at' => now()->addDays(30),
|
||||
]);
|
||||
|
||||
// Act
|
||||
$this->deletionService->deleteUser($user);
|
||||
|
||||
// Assert
|
||||
$this->assertDatabaseMissing(Token::class, [
|
||||
'id' => $userToken->getKey(),
|
||||
]);
|
||||
$this->assertDatabaseMissing(RefreshToken::class, [
|
||||
'id' => $userRefreshToken->getKey(),
|
||||
]);
|
||||
$this->assertDatabaseHas(Token::class, [
|
||||
'id' => $otherUserToken->getKey(),
|
||||
]);
|
||||
$this->assertDatabaseHas(RefreshToken::class, [
|
||||
'id' => $otherUserRefreshToken->getKey(),
|
||||
]);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user