Merge pull request #55873 from frappe/mergify/bp/version-15-hotfix/pr-55872

fix: pemission for whitelist functions (backport #55872)
This commit is contained in:
rohitwaghchaure
2026-06-13 19:03:18 +05:30
committed by GitHub
13 changed files with 42 additions and 25 deletions

View File

@@ -90,7 +90,14 @@ class BankClearance(Document):
@frappe.whitelist()
def update_clearance_date(self):
clearance_date_updated = False
payment_docs = []
for d in self.get("payment_entries"):
if d.payment_document not in payment_docs:
payment_docs.append(d.payment_document)
for doctype in payment_docs:
frappe.has_permission(doctype, "write", throw=True)
for d in self.get("payment_entries"):
if d.clearance_date:
if not d.payment_document:

View File

@@ -154,12 +154,13 @@ class RepostAccountingLedger(Document):
@frappe.whitelist()
def start_repost(account_repost_doc=str) -> None:
def start_repost(account_repost_doc: str | None = None) -> None:
from erpnext.accounts.general_ledger import make_reverse_gl_entries
frappe.flags.through_repost_accounting_ledger = True
if account_repost_doc:
repost_doc = frappe.get_doc("Repost Accounting Ledger", account_repost_doc)
repost_doc.check_permission("write")
if repost_doc.docstatus == 1:
# Prevent repost on invoices with deferred accounting

View File

@@ -511,7 +511,8 @@ def get_party_advance_account(party_type, party, company):
@frappe.whitelist()
def get_party_bank_account(party_type, party):
def get_party_bank_account(party_type: str, party: str):
frappe.has_permission("Bank Account", "read", throw=True)
return frappe.db.get_value("Bank Account", {"party_type": party_type, "party": party, "is_default": 1})

View File

@@ -471,7 +471,7 @@ def get_lead_details(lead, posting_date=None, company=None, doctype=None):
@frappe.whitelist()
def make_lead_from_communication(communication, ignore_communication_links=False):
def make_lead_from_communication(communication: str, ignore_communication_links: bool = False):
"""raise a issue from email"""
doc = frappe.get_doc("Communication", communication)
@@ -490,7 +490,6 @@ def make_lead_from_communication(communication, ignore_communication_links=False
}
)
lead.flags.ignore_mandatory = True
lead.flags.ignore_permissions = True
lead.insert()
lead_name = lead.name

View File

@@ -522,7 +522,9 @@ def auto_close_opportunity():
@frappe.whitelist()
def make_opportunity_from_communication(communication, company, ignore_communication_links=False):
def make_opportunity_from_communication(
communication: str, company: str, ignore_communication_links: bool = False
):
from erpnext.crm.doctype.lead.lead import make_lead_from_communication
doc = frappe.get_doc("Communication", communication)
@@ -540,7 +542,7 @@ def make_opportunity_from_communication(communication, company, ignore_communica
"opportunity_from": opportunity_from,
"party_name": lead,
}
).insert(ignore_permissions=True)
).insert()
link_communication_to_document(doc, "Opportunity", opportunity.name, ignore_communication_links)

View File

@@ -288,8 +288,6 @@ class BOMCreator(Document):
@frappe.whitelist()
def edit_qty(self, docname: str, qty: float):
self.check_permission("write")
if not frappe.db.exists("BOM Creator Item", {"name": docname, "parent": self.name}):
frappe.throw(_("BOM Creator Item {0} does not exist").format(docname))
@@ -364,8 +362,6 @@ class BOMCreator(Document):
@frappe.whitelist()
def add_item(self, **kwargs):
self.check_permission("write")
if isinstance(kwargs, str):
kwargs = frappe.parse_json(kwargs)
@@ -400,8 +396,6 @@ class BOMCreator(Document):
@frappe.whitelist()
def add_sub_assembly(self, **kwargs):
self.check_permission("write")
if isinstance(kwargs, str):
kwargs = frappe.parse_json(kwargs)
@@ -464,8 +458,6 @@ class BOMCreator(Document):
@frappe.whitelist()
def delete_node(self, **kwargs):
self.check_permission("write")
if isinstance(kwargs, str):
kwargs = frappe.parse_json(kwargs)

View File

@@ -176,7 +176,7 @@ class Workstation(Document):
doc.check_permission("write")
doc.append("time_logs", {"from_time": from_time, "employee": employee})
doc.save(ignore_permissions=True)
doc.save()
return doc
@@ -191,7 +191,7 @@ class Workstation(Document):
row.time_in_mins = time_diff_in_hours(row.to_time, row.from_time) / 60
row.completed_qty = qty
doc.save(ignore_permissions=True)
doc.save()
doc.submit()
return doc

View File

@@ -209,6 +209,8 @@ class TransactionDeletionRecord(Document):
@frappe.whitelist()
def start_deletion_tasks(self):
self.check_permission("write")
# This method is the entry point for the chain of events that follow
self.db_set("status", "Running")
self.enqueue_task(task="Delete Bins")

View File

@@ -335,7 +335,9 @@ def get_default_address(out, name):
@frappe.whitelist()
def get_contact_display(contact):
def get_contact_display(contact: str):
frappe.has_permission("Contact", "read", doc=contact, throw=True)
contact_info = frappe.db.get_value(
"Contact", contact, ["first_name", "last_name", "phone", "mobile_no"], as_dict=1
)
@@ -436,7 +438,9 @@ def get_attachments(delivery_stop):
@frappe.whitelist()
def get_driver_email(driver):
def get_driver_email(driver: str):
frappe.has_permission("Driver", "read", doc=driver, throw=True)
employee = frappe.db.get_value("Driver", driver, "employee")
email = frappe.db.get_value("Employee", employee, "prefered_email")
return {"email": email}

View File

@@ -123,7 +123,9 @@ def get_contact_name(ref_doctype, docname):
@frappe.whitelist()
def get_company_contact(user):
def get_company_contact(user: str):
frappe.has_permission("User", "read", throw=True)
contact = frappe.db.get_value(
"User",
user,

View File

@@ -134,12 +134,15 @@ def get_linked_cancelled_sabb(filters):
@frappe.whitelist()
def fix_sabb_entries(selected_rows):
def fix_sabb_entries(selected_rows: str | list):
frappe.has_permission("Serial and Batch Bundle", "write", throw=True)
if isinstance(selected_rows, str):
selected_rows = frappe.parse_json(selected_rows)
for row in selected_rows:
doc = frappe.get_doc("Serial and Batch Bundle", row.get("name"))
doc.check_permission("write")
if doc.is_cancelled == 0 and not frappe.db.get_value(
"Stock Ledger Entry",
{"serial_and_batch_bundle": doc.name, "is_cancelled": 0},

View File

@@ -3,6 +3,7 @@
import frappe
from frappe import _
from frappe.model.document import Document
from frappe.model.mapper import get_mapped_doc
from frappe.utils import flt
@@ -364,8 +365,9 @@ def get_mapped_subcontracting_receipt(source_name, target_doc=None):
@frappe.whitelist()
def update_subcontracting_order_status(sco, status=None):
def update_subcontracting_order_status(sco: str | Document, status: str | None = None):
if isinstance(sco, str):
sco = frappe.get_doc("Subcontracting Order", sco)
sco.check_permission("write")
sco.update_status(status)

View File

@@ -118,7 +118,9 @@ class Issue(Document):
communication.save()
@frappe.whitelist()
def split_issue(self, subject, communication_id):
def split_issue(self, subject: str, communication_id: str):
self.check_permission("write")
# Bug: Pressing enter doesn't send subject
from copy import deepcopy
@@ -274,7 +276,7 @@ def make_task(source_name, target_doc=None):
@frappe.whitelist()
def make_issue_from_communication(communication, ignore_communication_links=False):
def make_issue_from_communication(communication: str, ignore_communication_links: bool = False):
"""raise a issue from email"""
doc = frappe.get_doc("Communication", communication)
@@ -286,7 +288,7 @@ def make_issue_from_communication(communication, ignore_communication_links=Fals
"raised_by": doc.sender or "",
"raised_by_phone": doc.phone_no or "",
}
).insert(ignore_permissions=True)
).insert()
link_communication_to_document(doc, "Issue", issue.name, ignore_communication_links)