1 Commits
Author SHA1 Message Date
Meet PrajapatiandMeet Prajapati cf438f50b8 feat: allow employees to see their tracked data by default (#9874) (#10212)
Adds an organization setting `allowEmployeeToSeeTrackedData` (default true, so existing organizations
keep today's behaviour) that lets an admin hide an employee's own tracked data — screenshots,
activity, app/URL history, time logs, videos and statistics — from that employee.

- `EmployeeTrackedDataGuard` enforces it on the read routes of the activity, custom-tracking,
  statistic, time-log and time-slot controllers and of the videos, camshot and soundshot plugins.
  It depends only on the global DataSource, so plugins can use it.
- Exempt: admins (`CHANGE_SELECTED_EMPLOYEE`), callers with no employee record in the tenant,
  team/project managers of the organization, and the routes recording depends on — `time-slot/:id`,
  `time-log/:id`, `time-log/conflict`, `POST statistics/tasks` (the desktop timer's task picker)
  and every write route. A spec pins that list.
- The setting is read from the caller's own organization plus any organization the request names, so
  a client-chosen `organizationId` cannot bypass it, and the employee identity is read from the
  database rather than the token claim.
- `GET /timesheet/statistics/tracked-data-access` lets the web UI hide navigation with the same rule;
  the menus, the activity tabs and the dashboard widgets follow it, managers included.
- Adds the admin toggle, seeds, the SQLite/PostgreSQL/MySQL migration and i18n for all 14 locales,
  and removes a UTF-8 BOM from 11 locale files that broke locale loading in the desktop apps.

Resolves #9874.

Co-authored-by: Meet Prajapati <meet987654@users.noreply.github.com>
2026-09-20 10:49:02 +02:00