Adds an organization setting `allowEmployeeToSeeTrackedData` (default true, so existing organizations
keep today's behaviour) that lets an admin hide an employee's own tracked data — screenshots,
activity, app/URL history, time logs, videos and statistics — from that employee.
- `EmployeeTrackedDataGuard` enforces it on the read routes of the activity, custom-tracking,
statistic, time-log and time-slot controllers and of the videos, camshot and soundshot plugins.
It depends only on the global DataSource, so plugins can use it.
- Exempt: admins (`CHANGE_SELECTED_EMPLOYEE`), callers with no employee record in the tenant,
team/project managers of the organization, and the routes recording depends on — `time-slot/:id`,
`time-log/:id`, `time-log/conflict`, `POST statistics/tasks` (the desktop timer's task picker)
and every write route. A spec pins that list.
- The setting is read from the caller's own organization plus any organization the request names, so
a client-chosen `organizationId` cannot bypass it, and the employee identity is read from the
database rather than the token claim.
- `GET /timesheet/statistics/tracked-data-access` lets the web UI hide navigation with the same rule;
the menus, the activity tabs and the dashboard widgets follow it, managers included.
- Adds the admin toggle, seeds, the SQLite/PostgreSQL/MySQL migration and i18n for all 14 locales,
and removes a UTF-8 BOM from 11 locale files that broke locale loading in the desktop apps.
Resolves#9874.
Co-authored-by: Meet Prajapati <meet987654@users.noreply.github.com>