mirror of
https://github.com/frappe/erpnext.git
synced 2026-05-31 18:59:08 +00:00
db escape as single quote in address causes error (#13451)
This commit is contained in:
@@ -85,7 +85,7 @@ def delete_lead_addresses(company_name):
|
|||||||
in ({leads})""".format(leads=",".join(leads)))
|
in ({leads})""".format(leads=",".join(leads)))
|
||||||
|
|
||||||
if addresses:
|
if addresses:
|
||||||
addresses = ["'%s'"%addr for addr in addresses]
|
addresses = ["'%s'"%frappe.db.escape(addr) for addr in addresses]
|
||||||
|
|
||||||
frappe.db.sql("""delete from tabAddress where name in ({addresses}) and
|
frappe.db.sql("""delete from tabAddress where name in ({addresses}) and
|
||||||
name not in (select distinct dl1.parent from `tabDynamic Link` dl1
|
name not in (select distinct dl1.parent from `tabDynamic Link` dl1
|
||||||
|
|||||||
Reference in New Issue
Block a user