mirror of
https://github.com/frappe/erpnext.git
synced 2026-08-29 14:48:26 +00:00
* fix: keep source rate on re-fetch when maintain same rate is enabled (backport #57479) With "maintain same rate" on, re-fetching item details on a row mapped from a source document (e.g. a Purchase Order) pulled the latest Item Price, giving a rate the document can never be saved with. Skip the price list fetch for such rows and keep the source rate, both for a single-row re-fetch and the bulk apply_price_list path (price list / party / conversion rate change). The rate is read from the linked source row in the database (not the mutable target row) and permission-checked against the source document, so an unsaved edit can't lock in a different rate and a crafted request can't disclose another document's pricing. Fixes frappe/erpnext#57436 * fix: resolve linter findings in get_item_details Add missing type hints on the whitelisted get_item_details signature and rename maintain_same_rate_enabled's sole "args" parameter, both flagged by the semgrep security/code-quality rules. Also drops an extra blank line that ruff-format rejected. * fix: widen get_item_details doc type hint to include Document accounts_controller.py calls get_item_details(args, self, ...) during validate, passing the transaction Document itself, not a dict/JSON string. The narrower hint tripped Frappe's runtime argument type validation on every whitelisted call with a live Document, failing test-record creation across the suite.