mirror of
https://github.com/frappe/erpnext.git
synced 2026-08-15 07:28:39 +00:00
fix(tnc): get_terms_and_conditions render_template with safe_exec (backport #56944) (backport #56977) (#57106)
Co-authored-by: Diptanil Saha <diptanil@frappe.io>
This commit is contained in:
@@ -30,7 +30,7 @@ class TermsandConditions(Document):
|
|||||||
|
|
||||||
def validate(self):
|
def validate(self):
|
||||||
if self.terms:
|
if self.terms:
|
||||||
validate_template(self.terms)
|
validate_template(self.terms, restrict_globals=True)
|
||||||
if not cint(self.buying) and not cint(self.selling) and not cint(self.hr) and not cint(self.disabled):
|
if not cint(self.buying) and not cint(self.selling) and not cint(self.hr) and not cint(self.disabled):
|
||||||
throw(_("At least one of the Applicable Modules should be selected"))
|
throw(_("At least one of the Applicable Modules should be selected"))
|
||||||
|
|
||||||
@@ -40,7 +40,10 @@ def get_terms_and_conditions(template_name, doc):
|
|||||||
if isinstance(doc, str):
|
if isinstance(doc, str):
|
||||||
doc = json.loads(doc)
|
doc = json.loads(doc)
|
||||||
|
|
||||||
terms_and_conditions = frappe.get_doc("Terms and Conditions", template_name)
|
tnc = frappe.get_cached_doc("Terms and Conditions", template_name)
|
||||||
|
tnc.check_permission()
|
||||||
|
|
||||||
if terms_and_conditions.terms:
|
if not tnc.terms:
|
||||||
return frappe.render_template(terms_and_conditions.terms, doc)
|
return
|
||||||
|
|
||||||
|
return frappe.render_template(tnc.terms, doc, restrict_globals=1)
|
||||||
|
|||||||
Reference in New Issue
Block a user