mirror of
https://github.com/frappe/erpnext.git
synced 2026-08-02 17:24:36 +00:00
fix(tnc): get_terms_and_conditions render_template with safe_exec (backport #56944) (backport #56977) (#57106)
Co-authored-by: Diptanil Saha <diptanil@frappe.io>
This commit is contained in:
@@ -30,7 +30,7 @@ class TermsandConditions(Document):
|
||||
|
||||
def validate(self):
|
||||
if self.terms:
|
||||
validate_template(self.terms)
|
||||
validate_template(self.terms, restrict_globals=True)
|
||||
if not cint(self.buying) and not cint(self.selling) and not cint(self.hr) and not cint(self.disabled):
|
||||
throw(_("At least one of the Applicable Modules should be selected"))
|
||||
|
||||
@@ -40,7 +40,10 @@ def get_terms_and_conditions(template_name, doc):
|
||||
if isinstance(doc, str):
|
||||
doc = json.loads(doc)
|
||||
|
||||
terms_and_conditions = frappe.get_doc("Terms and Conditions", template_name)
|
||||
tnc = frappe.get_cached_doc("Terms and Conditions", template_name)
|
||||
tnc.check_permission()
|
||||
|
||||
if terms_and_conditions.terms:
|
||||
return frappe.render_template(terms_and_conditions.terms, doc)
|
||||
if not tnc.terms:
|
||||
return
|
||||
|
||||
return frappe.render_template(tnc.terms, doc, restrict_globals=1)
|
||||
|
||||
Reference in New Issue
Block a user