update HR dan Payroll
This commit is contained in:
@@ -11,6 +11,12 @@ class MY_Controller extends CI_Controller
|
||||
if (!$this->session->userdata('logged_in')) {
|
||||
$this->rejectUnauthenticatedRequest();
|
||||
}
|
||||
$this->load->library('UserSessionService');
|
||||
$sessionCheck=$this->usersessionservice->validateCurrent();
|
||||
if(!$sessionCheck['valid']){
|
||||
$reason=$sessionCheck['reason']==='expired'?'expired':($sessionCheck['reason']==='device_limit'?'device_limit':'revoked');
|
||||
$this->terminateAuthenticatedSession($reason);
|
||||
}
|
||||
if ($this->db->table_exists('companies')) {
|
||||
$this->load->library('CompanyContext');
|
||||
try {
|
||||
@@ -48,9 +54,9 @@ class MY_Controller extends CI_Controller
|
||||
'inventoryprofessional'=>'items','asset'=>'asset','fixedassets'=>'asset','lokasiasset'=>'asset',
|
||||
'cashbank'=>'cash_bank','jurnal'=>'jurnal','basejurnal'=>'jurnal','accounts'=>'jurnal',
|
||||
'accountingperiods'=>'jurnal','professionalreports'=>'reports','budgets'=>'budgets',
|
||||
'taxes'=>'taxes','roles'=>'setting','users'=>'setting','employees'=>'employees','generateschedule'=>'employees',
|
||||
'attendancemonitoring'=>'employees','attendancemonthly'=>'employees','attendancmonthly'=>'employees',
|
||||
'shifts'=>'employees','holidays'=>'employees','leaverequests'=>'employees','hrpayroll'=>'employees','organizationmaster'=>'employees'
|
||||
'taxes'=>'taxes','roles'=>'setting','users'=>'setting','employees'=>array('hr_employees','employees'),'generateschedule'=>array('hr_schedules','employees'),
|
||||
'attendancemonitoring'=>array('hr_attendance','employees'),'attendancemonthly'=>array('hr_attendance','employees'),'attendancmonthly'=>array('hr_attendance','employees'),
|
||||
'shifts'=>array('hr_schedules','employees'),'holidays'=>array('hr_schedules','employees'),'leaverequests'=>array('hr_leave','employees'),'hrpayroll'=>array('payroll','employees'),'payroll'=>array('payroll','employees'),'organizationmaster'=>array('hr_organization','employees')
|
||||
);
|
||||
if (!isset($features[$class])) return;
|
||||
$action = 'can_view';
|
||||
@@ -90,6 +96,52 @@ class MY_Controller extends CI_Controller
|
||||
}
|
||||
if (in_array($method, array('save_lines','revise'), true)) $action = 'can_update';
|
||||
}
|
||||
if ($class === 'leaverequests') {
|
||||
if (in_array($method, array('get_data','detail'), true)) $action = 'can_view';
|
||||
if ($method === 'save') $action = 'can_view';
|
||||
if ($method === 'submit') $action = 'can_create';
|
||||
if (in_array($method, array('approve','reject'), true)) $action = 'can_approve';
|
||||
if ($method === 'cancel') $action = 'can_view';
|
||||
}
|
||||
if ($class === 'attendancemonitoring') {
|
||||
if (in_array($method, array('get_data','manual_requests','manual_detail','employees'), true)) $action = 'can_view';
|
||||
if ($method === 'save_manual') $action = 'can_create';
|
||||
if ($method === 'submit_manual') $action = 'can_create';
|
||||
if (in_array($method, array('approve_manual','reject_manual'), true)) $action = 'can_approve';
|
||||
if ($method === 'cancel_manual') $action = 'can_update';
|
||||
}
|
||||
if ($class === 'employees') {
|
||||
if (in_array($method,array('getall','detail'),true)) $action='can_view';
|
||||
if ($method==='store') $action='can_create';
|
||||
if ($method==='update') $action='can_update';
|
||||
if ($method==='delete') $action='can_delete';
|
||||
}
|
||||
if ($class === 'organizationmaster') {
|
||||
if (in_array($method,array('index','data'),true)) $action='can_view';
|
||||
if (in_array($method,array('save_department','save_position'),true)) $action=$this->input->post('id')?'can_update':'can_create';
|
||||
if (strpos($method,'delete_')===0) $action='can_delete';
|
||||
}
|
||||
if ($class === 'generateschedule') {
|
||||
if (in_array($method,array('index','calendar_data','get_employees','detail_schedule'),true)) $action='can_view';
|
||||
if ($method==='save_manual_schedule') $action='can_create';
|
||||
if ($method==='update_schedule_shift') $action='can_update';
|
||||
if ($method==='delete_schedule') $action='can_delete';
|
||||
}
|
||||
if (in_array($class,array('shifts','holidays'),true)) {
|
||||
if (in_array($method,array('index','get_data','detail'),true)) $action='can_view';
|
||||
if ($method==='save') $action='can_create';
|
||||
if ($method==='update') $action='can_update';
|
||||
if ($method==='delete') $action='can_delete';
|
||||
}
|
||||
if (in_array($class,array('attendancemonthly','attendancmonthly'),true)) $action='can_view';
|
||||
if ($class === 'hrpayroll') {
|
||||
if (in_array($method, array('index','period_detail','salary_detail','slip'), true)) $action = 'can_view';
|
||||
if (strpos($method,'export')!==false) $action = 'can_export';
|
||||
if (in_array($method, array('create_period','calculate','save_adjustment'), true)) $action = 'can_create';
|
||||
if (in_array($method, array('component','save_salary_line','deactivate_salary_line','save_position_line','save_attendance_rule','save_settings','deactivate_adjustment'), true)) $action = 'can_update';
|
||||
if ($method === 'workflow') $action = 'can_approve';
|
||||
if (in_array($method, array('lock_attendance','post','pay'), true)) $action = 'can_post';
|
||||
}
|
||||
if ($class === 'sales') {
|
||||
if (in_array($method, array('invoice_detail','delivery_detail','return_detail','lookup_customers','lookup_items','lookup_barcodes','warehouses'), true)) $action = 'can_view';
|
||||
if (in_array($method, array('append_invoice','delete_invoice','update_delivery'), true)) $action = 'can_update';
|
||||
@@ -135,13 +187,36 @@ class MY_Controller extends CI_Controller
|
||||
exit;
|
||||
}
|
||||
|
||||
protected function terminateAuthenticatedSession($reason)
|
||||
{
|
||||
$messages=array(
|
||||
'expired'=>'Masa login Anda telah berakhir. Silakan login kembali.',
|
||||
'device_limit'=>'Session dihentikan karena batas perangkat aktif telah tercapai.',
|
||||
'revoked'=>'Session perangkat ini telah diakhiri. Silakan login kembali.',
|
||||
);
|
||||
$message=$messages[$reason]??$messages['revoked'];
|
||||
$this->usersessionservice->endCurrent($reason==='expired'?'expired':'revoked',$message);
|
||||
$this->session->sess_destroy();
|
||||
if($this->input->is_ajax_request()){
|
||||
$this->output->set_status_header(401)->set_content_type('application/json')->set_output(json_encode(array('status'=>false,'message'=>$message,'redirect'=>base_url('auth'))))->_display();
|
||||
exit;
|
||||
}
|
||||
redirect('auth?notice='.rawurlencode($reason));
|
||||
exit;
|
||||
}
|
||||
|
||||
protected function requirePermission($feature, $action = 'can_view')
|
||||
{
|
||||
if (is_master_admin_user()) {
|
||||
return true;
|
||||
}
|
||||
|
||||
if (!check_permission($feature, $action)) {
|
||||
$features = is_array($feature) ? $feature : array($feature);
|
||||
$allowed = false;
|
||||
foreach ($features as $permissionFeature) {
|
||||
if (check_permission($permissionFeature, $action)) { $allowed = true; break; }
|
||||
}
|
||||
if (!$allowed) {
|
||||
if ($this->input->is_ajax_request()) {
|
||||
$this->output->set_status_header(403)->set_content_type('application/json','utf-8')->set_output(json_encode(array('status'=>false,'message'=>'Anda tidak memiliki izin untuk tindakan ini.')))->_display();
|
||||
exit;
|
||||
|
||||
Reference in New Issue
Block a user