fix(accounts): add permission checks on invoice_discounting.get_invoices (backport #58975) (#58990)

Co-authored-by: Diptanil Saha <diptanil@frappe.io>
This commit is contained in:
mergify[bot]
2026-09-11 04:30:00 +00:00
committed by GitHub
parent d0b8379404
commit a9f3d69fbe
3 changed files with 15 additions and 7 deletions

View File

@@ -136,6 +136,7 @@ frappe.ui.form.on("Invoice Discounting", {
], ],
primary_action: function () { primary_action: function () {
var data = d.get_values(); var data = d.get_values();
data.company = frm.doc.company;
frappe.call({ frappe.call({
method: "erpnext.accounts.doctype.invoice_discounting.invoice_discounting.get_invoices", method: "erpnext.accounts.doctype.invoice_discounting.invoice_discounting.get_invoices",

View File

@@ -1,5 +1,6 @@
{ {
"actions": [], "actions": [],
"allow_bulk_edit": 1,
"allow_import": 1, "allow_import": 1,
"autoname": "ACC-INV-DISC-.YYYY.-.#####", "autoname": "ACC-INV-DISC-.YYYY.-.#####",
"creation": "2019-03-07 12:01:56.296952", "creation": "2019-03-07 12:01:56.296952",
@@ -170,7 +171,7 @@
], ],
"is_submittable": 1, "is_submittable": 1,
"links": [], "links": [],
"modified": "2024-03-27 13:09:52.746196", "modified": "2026-09-09 17:04:59.512294",
"modified_by": "Administrator", "modified_by": "Administrator",
"module": "Accounts", "module": "Accounts",
"name": "Invoice Discounting", "name": "Invoice Discounting",
@@ -187,14 +188,15 @@
"print": 1, "print": 1,
"read": 1, "read": 1,
"report": 1, "report": 1,
"role": "System Manager", "role": "Accounts Manager",
"share": 1, "share": 1,
"submit": 1, "submit": 1,
"write": 1 "write": 1
} }
], ],
"row_format": "Dynamic",
"sort_field": "creation", "sort_field": "creation",
"sort_order": "DESC", "sort_order": "DESC",
"states": [], "states": [],
"track_changes": 1 "track_changes": 1
} }

View File

@@ -2,8 +2,6 @@
# For license information, please see license.txt # For license information, please see license.txt
import json
import frappe import frappe
from frappe import _ from frappe import _
from frappe.utils import add_days, flt, getdate, nowdate from frappe.utils import add_days, flt, getdate, nowdate
@@ -317,8 +315,15 @@ class InvoiceDiscounting(AccountsController):
@frappe.whitelist() @frappe.whitelist()
def get_invoices(filters): def get_invoices(filters: str | dict):
filters = frappe._dict(json.loads(filters)) filters = frappe._dict(frappe.parse_json(filters))
if not filters.get("company"):
frappe.throw(_("Please set company on the Document before requesting for invoices."))
frappe.has_permission("Company", doc=filters.get("company"), throw=True)
frappe.has_permission("Invoice Discounting", throw=True)
cond = [] cond = []
if filters.customer: if filters.customer:
cond.append("customer=%(customer)s") cond.append("customer=%(customer)s")