From c2261f6129417fde39294c2bf46f9edd52e8e5ab Mon Sep 17 00:00:00 2001 From: Shllokkk Date: Fri, 21 Aug 2026 13:18:26 +0530 Subject: [PATCH] fix(crm): check write permission in edit_note (cherry picked from commit eb49f51d29330bec3761d69c0ca12a79bce14fb0) # Conflicts: # erpnext/crm/utils.py --- erpnext/crm/utils.py | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/erpnext/crm/utils.py b/erpnext/crm/utils.py index a2204ab316f..7be10e647d8 100644 --- a/erpnext/crm/utils.py +++ b/erpnext/crm/utils.py @@ -255,7 +255,14 @@ class CRMNote(Document): notify_mentions(self.doctype, self.name, note) @frappe.whitelist() +<<<<<<< HEAD def edit_note(self, note, row_id): +======= + def edit_note(self, note: str, row_id: str): + # db_update() skips the write check that save() does in add_note/delete_note + self.check_permission("write") + +>>>>>>> eb49f51 (fix(crm): check write permission in edit_note) for d in self.notes: if cstr(d.name) == row_id: d.note = note