mirror of
https://github.com/frappe/erpnext.git
synced 2026-09-17 02:26:33 +00:00
Treeview permission (#14232)
* Replace frappe.db.sql to frappe.get_list to apply permissions (#14037) * Replace frappe.db.sql to frappe.get_list to apply permission - All get_children method had frappe.db.sql in them which had no permission check, now its replaced with frappe.get_list which will check permission based on the user. * Fix codacy - Remove trailing whitespace * Add parent filter * Add ifnull checks
This commit is contained in:
@@ -626,18 +626,28 @@ def get_children(doctype, parent=None, is_root=False, **filters):
|
||||
return
|
||||
|
||||
if frappe.form_dict.parent:
|
||||
return frappe.db.sql("""select
|
||||
bom_item.item_code,
|
||||
bom_item.bom_no as value,
|
||||
bom_item.stock_qty,
|
||||
if(ifnull(bom_item.bom_no, "")!="", 1, 0) as expandable,
|
||||
item.image,
|
||||
item.description
|
||||
from `tabBOM Item` bom_item, tabItem item
|
||||
where bom_item.parent=%s
|
||||
and bom_item.item_code = item.name
|
||||
order by bom_item.idx
|
||||
""", frappe.form_dict.parent, as_dict=True)
|
||||
bom_items = frappe.get_list('BOM Item',
|
||||
fields=['item_code', 'bom_no as value', 'stock_qty'],
|
||||
filters=[['parent', '=', frappe.form_dict.parent]],
|
||||
order_by='idx')
|
||||
|
||||
item_names = tuple(d.get('item_code') for d in bom_items)
|
||||
|
||||
items = frappe.get_list('Item',
|
||||
fields=['image', 'description', 'name'],
|
||||
filters=[['name', 'in', item_names]]) # to get only required item dicts
|
||||
|
||||
for bom_item in bom_items:
|
||||
# extend bom_item dict with respective item dict
|
||||
bom_item.update(
|
||||
# returns an item dict from items list which matches with item_code
|
||||
(item for item in items if item.get('name')
|
||||
== bom_item.get('item_code')).next()
|
||||
)
|
||||
bom_item.expandable = 0 if bom_item.value in ('', None) else 1
|
||||
|
||||
return bom_items
|
||||
|
||||
|
||||
def get_boms_in_bottom_up_order(bom_no=None):
|
||||
def _get_parent(bom_no):
|
||||
|
||||
Reference in New Issue
Block a user