Skip to content

Commit e7ee824

Browse files
authored
Merge pull request #3020 from TechnologyEnhancedLearning/Develop/Features/TD-4884-Reviewpageisstillaccessibleforthisadmintoconfirmtheresults
TD-4884 Prevent supervisors from confirm self assessments in a category that doesn't match their own
2 parents 7949fa8 + 1f61456 commit e7ee824

File tree

4 files changed

+21
-14
lines changed

4 files changed

+21
-14
lines changed

DigitalLearningSolutions.Data/DataServices/SupervisorDataService.cs

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ public interface ISupervisorDataService
2222
DelegateSelfAssessment? GetSelfAssessmentByCandidateAssessmentId(int candidateAssessmentId, int adminId, int? adminIdCategoryId);
2323
IEnumerable<SupervisorDashboardToDoItem> GetSupervisorDashboardToDoItemsForRequestedSignOffs(int adminId);
2424
IEnumerable<SupervisorDashboardToDoItem> GetSupervisorDashboardToDoItemsForRequestedReviews(int adminId);
25-
DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId);
25+
DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId, int? adminIdCategoryId);
2626
IEnumerable<RoleProfile> GetAvailableRoleProfilesForDelegate(int candidateId, int centreId, int? categoryId);
2727
RoleProfile? GetRoleProfileById(int selfAssessmentId);
2828
IEnumerable<SelfAssessmentSupervisorRole> GetSupervisorRolesForSelfAssessment(int selfAssessmentId);
@@ -594,7 +594,7 @@ FROM CandidateAssessmentSupervisors AS cas INNER JOIN
594594
WHERE (ca.RemovedDate IS NULL) AND (cas.SupervisorDelegateId = @supervisorDelegateId) AND (cas.Removed IS NULL) AND (sa.ID = @selfAssessmentId)", new { selfAssessmentId, supervisorDelegateId }
595595
).FirstOrDefault();
596596
}
597-
public DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId)
597+
public DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId, int? adminIdCategoryId)
598598
{
599599
return connection.Query<DelegateSelfAssessment>(
600600
@$"SELECT ca.ID, sa.ID AS SelfAssessmentID, sa.Name AS RoleName, sa.QuestionLabel, sa.DescriptionLabel, sa.ReviewerCommentsLabel,
@@ -611,7 +611,7 @@ FROM SelfAssessmentResultSupervisorVerifications AS sarsv
611611
FROM CandidateAssessmentSupervisors AS cas INNER JOIN
612612
CandidateAssessments AS ca ON cas.CandidateAssessmentID = ca.ID INNER JOIN
613613
SelfAssessments AS sa ON sa.ID = ca.SelfAssessmentID
614-
WHERE (ca.ID = @candidateAssessmentId)", new { candidateAssessmentId }
614+
WHERE (ca.ID = @candidateAssessmentId) AND (ISNULL(@adminIdCategoryID, 0) = 0 OR sa.CategoryID = @adminIdCategoryId)", new { candidateAssessmentId, adminIdCategoryId }
615615
).FirstOrDefault();
616616
}
617617
public DelegateSelfAssessment? GetSelfAssessmentBySupervisorDelegateCandidateAssessmentId(int candidateAssessmentId, int supervisorDelegateId)

DigitalLearningSolutions.Web/Controllers/SupervisorController/Supervisor.cs

Lines changed: 12 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -515,7 +515,7 @@ int resultId
515515
)
516516
{
517517
var model = ReviewCompetencySelfAsessmentData(supervisorDelegateId, candidateAssessmentId, resultId);
518-
518+
if (model == null) return RedirectToAction("StatusCode", "LearningSolutions", new { code = 403 });
519519
return View("ReviewCompetencySelfAsessment", model);
520520
}
521521

@@ -587,8 +587,10 @@ int resultId
587587
candidateAssessmentId,
588588
adminId
589589
);
590+
var loggedInAdminUser = userService.GetAdminUserById(adminId);
590591
var delegateSelfAssessment =
591-
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId);
592+
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId, loggedInAdminUser.CategoryId);
593+
if (delegateSelfAssessment == null) return null;
592594
var assessmentQuestion = GetLevelDescriptorsForAssessmentQuestion(competency.AssessmentQuestions.First());
593595
competency.CompetencyFlags = frameworkService.GetSelectedCompetencyFlagsByCompetecyId(competency.Id);
594596
var model = new ReviewCompetencySelfAsessmentViewModel()
@@ -610,10 +612,12 @@ int resultId
610612
public IActionResult VerifyMultipleResults(int supervisorDelegateId, int candidateAssessmentId)
611613
{
612614
var adminId = GetAdminId();
615+
var loggedInAdminUser = userService.GetAdminUserById(adminId);
613616
var superviseDelegate =
614617
supervisorService.GetSupervisorDelegateDetailsById(supervisorDelegateId, GetAdminId(), 0);
615618
var delegateSelfAssessment =
616-
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId);
619+
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId, loggedInAdminUser.CategoryId);
620+
if (delegateSelfAssessment == null) return RedirectToAction("StatusCode", "LearningSolutions", new { code = 403 });
617621
var reviewedCompetencies = PopulateCompetencyLevelDescriptors(
618622
selfAssessmentService.GetCandidateAssessmentResultsForReviewById(candidateAssessmentId, adminId)
619623
.ToList()
@@ -638,10 +642,11 @@ List<int> resultChecked
638642
if (resultChecked.Count == 0)
639643
{
640644
var adminId = GetAdminId();
645+
var loggedInAdminUser = userService.GetAdminUserById(adminId);
641646
var superviseDelegate =
642647
supervisorService.GetSupervisorDelegateDetailsById(supervisorDelegateId, GetAdminId(), 0);
643648
var delegateSelfAssessment =
644-
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId);
649+
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId, loggedInAdminUser.CategoryId);
645650
var reviewedCompetencies = PopulateCompetencyLevelDescriptors(
646651
selfAssessmentService.GetCandidateAssessmentResultsForReviewById(candidateAssessmentId, adminId)
647652
.ToList()
@@ -1260,10 +1265,12 @@ SignOffProfileAssessmentViewModel model
12601265
public IActionResult SignOffHistory(int supervisorDelegateId, int candidateAssessmentId)
12611266
{
12621267
var adminId = GetAdminId();
1268+
var loggedInAdminUser = userService.GetAdminUserById(adminId);
12631269
var superviseDelegate =
12641270
supervisorService.GetSupervisorDelegateDetailsById(supervisorDelegateId, GetAdminId(), 0);
12651271
var delegateSelfAssessment =
1266-
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId);
1272+
supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId, loggedInAdminUser.CategoryId);
1273+
if (delegateSelfAssessment == null) return RedirectToAction("StatusCode", "LearningSolutions", new { code = 403 });
12671274
var model = new SignOffHistoryViewModel()
12681275
{
12691276
DelegateSelfAssessment = delegateSelfAssessment,

DigitalLearningSolutions.Web/Services/FrameworkNotificationService.cs

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -351,7 +351,7 @@ public void SendResultVerificationRequest(int candidateAssessmentSupervisorId, i
351351
int candidateAssessmentId = candidateAssessmentSupervisor.CandidateAssessmentID;
352352
var supervisorDelegate = supervisorService.GetSupervisorDelegateDetailsById(supervisorDelegateId, 0, delegateUserId);
353353
string centreName = GetCentreName(centreId);
354-
var delegateSelfAssessment = supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentSupervisor.CandidateAssessmentID);
354+
var delegateSelfAssessment = supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentSupervisor.CandidateAssessmentID, 0);
355355
string emailSubjectLine = $"{delegateSelfAssessment.SupervisorRoleTitle} Self Assessment Results Review Request - Digital Learning Solutions";
356356
string? profileReviewUrl = GetSupervisorProfileReviewUrl(supervisorDelegateId, candidateAssessmentId, selfAssessmentResultId);
357357
BodyBuilder? builder = new BodyBuilder();
@@ -369,7 +369,7 @@ public void SendSignOffRequest(int candidateAssessmentSupervisorId, int selfAsse
369369
int candidateAssessmentId = candidateAssessmentSupervisor.CandidateAssessmentID;
370370
var supervisorDelegate = supervisorService.GetSupervisorDelegateDetailsById(supervisorDelegateId, 0, delegateUserId);
371371
string centreName = GetCentreName(centreId);
372-
var delegateSelfAssessment = supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentSupervisor.CandidateAssessmentID);
372+
var delegateSelfAssessment = supervisorService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentSupervisor.CandidateAssessmentID, 0);
373373
string emailSubjectLine = $"{delegateSelfAssessment.SupervisorRoleTitle} Self Assessment Sign-off Request - Digital Learning Solutions";
374374
string? profileReviewUrl = GetSupervisorProfileReviewUrl(supervisorDelegateId, candidateAssessmentId);
375375
BodyBuilder? builder = new BodyBuilder();

DigitalLearningSolutions.Web/Services/SupervisorService.cs

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ public interface ISupervisorService
1919
DelegateSelfAssessment? GetSelfAssessmentByCandidateAssessmentId(int candidateAssessmentId, int adminId, int? adminIdCategoryId);
2020
IEnumerable<SupervisorDashboardToDoItem> GetSupervisorDashboardToDoItemsForRequestedSignOffs(int adminId);
2121
IEnumerable<SupervisorDashboardToDoItem> GetSupervisorDashboardToDoItemsForRequestedReviews(int adminId);
22-
DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId);
22+
DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId, int? adminIdCategoryId);
2323
IEnumerable<RoleProfile> GetAvailableRoleProfilesForDelegate(int candidateId, int centreId, int? categoryId);
2424
RoleProfile? GetRoleProfileById(int selfAssessmentId);
2525
IEnumerable<SelfAssessmentSupervisorRole> GetSupervisorRolesForSelfAssessment(int selfAssessmentId);
@@ -115,9 +115,9 @@ public IEnumerable<SelfAssessmentSupervisorRole> GetDelegateNominatableSuperviso
115115
return supervisorDataService.GetRoleProfileById(selfAssessmentId);
116116
}
117117

118-
public DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId)
118+
public DelegateSelfAssessment? GetSelfAssessmentBaseByCandidateAssessmentId(int candidateAssessmentId, int? adminIdCategoryId)
119119
{
120-
return supervisorDataService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId);
120+
return supervisorDataService.GetSelfAssessmentBaseByCandidateAssessmentId(candidateAssessmentId, adminIdCategoryId);
121121
}
122122

123123
public DelegateSelfAssessment? GetSelfAssessmentByCandidateAssessmentId(int candidateAssessmentId, int adminId, int? adminIdCategoryId)
@@ -275,7 +275,7 @@ public IEnumerable<SupervisorDelegateDetail> GetSupervisorDelegateDetailsForAdmi
275275
}
276276
public SupervisorDelegateDetail GetSupervisorDelegateDetailsByIdWithoutRemoveClause(int supervisorDelegateId, int adminId, int delegateUserId)
277277
{
278-
return supervisorDataService.GetSupervisorDelegateDetailsByIdWithoutRemoveClause(supervisorDelegateId,adminId, delegateUserId);
278+
return supervisorDataService.GetSupervisorDelegateDetailsByIdWithoutRemoveClause(supervisorDelegateId, adminId, delegateUserId);
279279
}
280280
}
281281
}

0 commit comments

Comments
 (0)