Merge pull request #56194 from frappe/mergify/bp/version-16-hotfix/pr-56191

fix: added missing permission validation on whitelisted function and removed unnecessary whitelisted decorator (backport #56191)
This commit is contained in:
Diptanil Saha
2026-06-20 20:25:41 +05:30
committed by GitHub
2 changed files with 4 additions and 1 deletions

View File

@@ -616,6 +616,10 @@ def calculate_exchange_rate_using_last_gle(company, account, party_type, party):
def get_account_details(
company, posting_date, account, party_type=None, party=None, rounding_loss_allowance: float | None = None
):
if not account:
return
frappe.has_permission("Account", doc=account, throw=True)
if not (company and posting_date):
frappe.throw(_("Company and Posting Date is mandatory"))

View File

@@ -146,7 +146,6 @@ def get_appropriate_company(filters):
return company
@frappe.whitelist()
def get_invoiced_item_gross_margin(sales_invoice=None, item_code=None, company=None, with_item_data=False):
from erpnext.accounts.report.gross_profit.gross_profit import GrossProfitGenerator