From b481083ff002ce543b4f8eb87cc3a65559da54f5 Mon Sep 17 00:00:00 2001 From: Diptanil Saha Date: Fri, 11 Sep 2026 09:39:38 +0530 Subject: [PATCH] fix(accounts): add permission checks on `invoice_discounting.get_invoices` (#58975) --- .../doctype/invoice_discounting/invoice_discounting.js | 1 + .../doctype/invoice_discounting/invoice_discounting.json | 8 +++++--- .../doctype/invoice_discounting/invoice_discounting.py | 7 +++++++ 3 files changed, 13 insertions(+), 3 deletions(-) diff --git a/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.js b/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.js index 1e73c669d84..6e533168602 100644 --- a/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.js +++ b/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.js @@ -136,6 +136,7 @@ frappe.ui.form.on("Invoice Discounting", { ], primary_action: function () { var data = d.get_values(); + data.company = frm.doc.company; frappe.call({ method: "erpnext.accounts.doctype.invoice_discounting.invoice_discounting.get_invoices", diff --git a/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.json b/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.json index bc389465c4d..39755d84e5c 100644 --- a/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.json +++ b/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.json @@ -1,5 +1,6 @@ { "actions": [], + "allow_bulk_edit": 1, "allow_import": 1, "autoname": "ACC-INV-DISC-.YYYY.-.#####", "creation": "2019-03-07 12:01:56.296952", @@ -170,7 +171,7 @@ ], "is_submittable": 1, "links": [], - "modified": "2024-03-27 13:09:52.746196", + "modified": "2026-09-09 17:04:59.512294", "modified_by": "Administrator", "module": "Accounts", "name": "Invoice Discounting", @@ -187,14 +188,15 @@ "print": 1, "read": 1, "report": 1, - "role": "System Manager", + "role": "Accounts Manager", "share": 1, "submit": 1, "write": 1 } ], + "row_format": "Dynamic", "sort_field": "creation", "sort_order": "DESC", "states": [], "track_changes": 1 -} \ No newline at end of file +} diff --git a/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.py b/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.py index bf4f9e072d0..ffdb27bc476 100644 --- a/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.py +++ b/erpnext/accounts/doctype/invoice_discounting/invoice_discounting.py @@ -319,6 +319,13 @@ class InvoiceDiscounting(AccountsController): @frappe.whitelist() def get_invoices(filters: str | dict): filters = frappe._dict(frappe.parse_json(filters)) + + if not filters.get("company"): + frappe.throw(_("Please set company on the Document before requesting for invoices.")) + + frappe.has_permission("Company", doc=filters.get("company"), throw=True) + frappe.has_permission("Invoice Discounting", throw=True) + si = frappe.qb.DocType("Sales Invoice") di = frappe.qb.DocType("Discounted Invoice")