Monday, August 31, 2026
1 change · saas-19.2
Security fixes and vulnerability patches
The Attendance Gantt view no longer shows employees without attendance records to users who are only allowed to manage their own attendance. This prevents employees from being unnecessarily exposed in the schedule view and keeps the display aligned with each user's access rights.
Original PR description
Issue: ---------------------------------------- A user with the group "Attendance: Self Attendance Edit" sees all employees when opening the Attendance Gantt view even though they can only see their attendances. Steps to reproduce: ---------------------------------------- - Have a user with the group "Attendance: Self Attendance Edit" - Connect as this user - Open Attendances - In the Gantt view they can see all employees (not their attendances) Cause: ---------------------------------------- `_get_gantt_data_group_by_employee()` is adding all the employees without attendances to the result of `get_gantt_data()`. Solution: ---------------------------------------- We condition the addition of employees without attendances with the ability of the user to see other employees' attendances. opw-6295888