fix(tnc): get_terms_and_conditions render_template with safe_exec (backport #56944) (backport #56977) (#57106)

Co-authored-by: Diptanil Saha <diptanil@frappe.io>
This commit is contained in:
mergify[bot]
2026-07-28 21:59:17 +05:30
committed by GitHub
parent 41effcf754
commit 1d60ab449c

View File

@@ -30,7 +30,7 @@ class TermsandConditions(Document):
def validate(self):
if self.terms:
validate_template(self.terms)
validate_template(self.terms, restrict_globals=True)
if not cint(self.buying) and not cint(self.selling) and not cint(self.hr) and not cint(self.disabled):
throw(_("At least one of the Applicable Modules should be selected"))
@@ -40,7 +40,10 @@ def get_terms_and_conditions(template_name, doc):
if isinstance(doc, str):
doc = json.loads(doc)
terms_and_conditions = frappe.get_doc("Terms and Conditions", template_name)
tnc = frappe.get_cached_doc("Terms and Conditions", template_name)
tnc.check_permission()
if terms_and_conditions.terms:
return frappe.render_template(terms_and_conditions.terms, doc)
if not tnc.terms:
return
return frappe.render_template(tnc.terms, doc, restrict_globals=1)