mirror of
https://github.com/frappe/erpnext.git
synced 2026-08-30 15:09:47 +00:00
Replace frappe.db.sql to frappe.get_list to apply permissions (#14037)
* Replace frappe.db.sql to frappe.get_list to apply permission - All get_children method had frappe.db.sql in them which had no permission check, now its replaced with frappe.get_list which will check permission based on the user. * Fix codacy - Remove trailing whitespace
This commit is contained in:
committed by
Rushabh Mehta
parent
11f3e8155b
commit
8501010f12
@@ -186,27 +186,25 @@ def set_tasks_as_overdue():
|
||||
|
||||
@frappe.whitelist()
|
||||
def get_children(doctype, parent, task=None, project=None, is_root=False):
|
||||
conditions = ''
|
||||
|
||||
filters = [['docstatus', '<', '2']]
|
||||
|
||||
if task:
|
||||
# via filters
|
||||
conditions += ' and parent_task = "{0}"'.format(frappe.db.escape(task))
|
||||
filters.append(['parent_task', '=', task])
|
||||
elif parent and not is_root:
|
||||
# via expand child
|
||||
conditions += ' and parent_task = "{0}"'.format(frappe.db.escape(parent))
|
||||
filters.append(['parent_task', '=', parent])
|
||||
else:
|
||||
conditions += ' and ifnull(parent_task, "")=""'
|
||||
filters.append(['parent_task', '=', ''])
|
||||
|
||||
if project:
|
||||
conditions += ' and project = "{0}"'.format(frappe.db.escape(project))
|
||||
filters.append(['project', '=', project])
|
||||
|
||||
tasks = frappe.db.sql("""select name as value,
|
||||
subject as title,
|
||||
is_group as expandable
|
||||
from `tabTask`
|
||||
where docstatus < 2
|
||||
{conditions}
|
||||
order by name""".format(conditions=conditions), as_dict=1)
|
||||
tasks = frappe.get_list(doctype, fields=[
|
||||
'name as value',
|
||||
'subject as title',
|
||||
'is_group as expandable'
|
||||
], filters=filters, order_by='name')
|
||||
|
||||
# return tasks
|
||||
return tasks
|
||||
|
||||
Reference in New Issue
Block a user