Ver a proveniência

[fix] escape quotes in permission conditions

version-14
Anand Doshi há 10 anos
ascendente
cometimento
c645111800
1 ficheiros alterados com 1 adições e 1 eliminações
  1. +1
    -1
      frappe/model/db_query.py

+ 1
- 1
frappe/model/db_query.py Ver ficheiro

@@ -279,7 +279,7 @@ class DatabaseQuery(object):
or `tab{doctype}`.`{fieldname}` in ({values}))""".format( or `tab{doctype}`.`{fieldname}` in ({values}))""".format(
doctype=self.doctype, doctype=self.doctype,
fieldname=df.fieldname, fieldname=df.fieldname,
values=", ".join([('"'+v.replace('"', '\"')+'"') for v in user_permissions[df.options]])
values=", ".join([('"'+frappe.db.escape(v)+'"') for v in user_permissions[df.options]])
)) ))
match_filters[df.options] = user_permissions[df.options] match_filters[df.options] = user_permissions[df.options]




Carregando…
Cancelar
Guardar