fix(tnc): get_terms_and_conditions render_template with safe_exec (#56944)

This commit is contained in:
Diptanil Saha
2026-07-08 05:48:35 +05:30
committed by GitHub
parent 8a940af7e1
commit 95212e5738

View File

@@ -30,7 +30,7 @@ class TermsandConditions(Document):
def validate(self):
if self.terms:
validate_template(self.terms)
validate_template(self.terms, restrict_globals=True)
if not cint(self.buying) and not cint(self.selling) and not cint(self.hr) and not cint(self.disabled):
throw(_("At least one of the Applicable Modules should be selected"))
@@ -39,7 +39,7 @@ class TermsandConditions(Document):
def get_terms_and_conditions(template_name: str, doc: str | dict):
doc = frappe.parse_json(doc)
terms_and_conditions = frappe.get_doc("Terms and Conditions", template_name)
terms = frappe.get_cached_value("Terms and Conditions", template_name, "terms")
if terms_and_conditions.terms:
return frappe.render_template(terms_and_conditions.terms, doc)
if terms:
return frappe.render_template(terms, doc, restrict_globals=True)