Minor fixes: escaped charactersversion-14
@@ -27,8 +27,8 @@ def get_permission_query_conditions(user): | |||||
`tabEvent Role`.parent=tabEvent.name | `tabEvent Role`.parent=tabEvent.name | ||||
and `tabEvent Role`.role in ('%(roles)s'))) | and `tabEvent Role`.role in ('%(roles)s'))) | ||||
""" % { | """ % { | ||||
"user": user, | |||||
"roles": "', '".join(frappe.get_roles(user)) | |||||
"user": frappe.db.escape(user), | |||||
"roles": "', '".join([frappe.db.escape(r) for r in frappe.get_roles(user)]) | |||||
} | } | ||||
def has_permission(doc, user): | def has_permission(doc, user): | ||||
@@ -77,7 +77,8 @@ def get_permission_query_conditions(user): | |||||
if "System Manager" in frappe.get_roles(user): | if "System Manager" in frappe.get_roles(user): | ||||
return None | return None | ||||
else: | else: | ||||
return """(tabToDo.owner = '{user}' or tabToDo.assigned_by = '{user}')""".format(user=user) | |||||
return """(tabToDo.owner = '{user}' or tabToDo.assigned_by = '{user}')"""\ | |||||
.format(user=frappe.db.escape(user)) | |||||
def has_permission(doc, user): | def has_permission(doc, user): | ||||
if "System Manager" in frappe.get_roles(user): | if "System Manager" in frappe.get_roles(user): | ||||
@@ -187,11 +187,11 @@ def make_test_objects(doctype, test_records, verbose=None): | |||||
records = [] | records = [] | ||||
if not frappe.get_meta(doctype).issingle: | if not frappe.get_meta(doctype).issingle: | ||||
existing = frappe.get_list(doctype, filters={"name":("like", "_T-" + doctype + "-%")}) | |||||
existing = frappe.get_all(doctype, filters={"name":("like", "_T-" + doctype + "-%")}) | |||||
if existing: | if existing: | ||||
return [d.name for d in existing] | return [d.name for d in existing] | ||||
existing = frappe.get_list(doctype, filters={"name":("like", "_Test " + doctype + "%")}) | |||||
existing = frappe.get_all(doctype, filters={"name":("like", "_Test " + doctype + "%")}) | |||||
if existing: | if existing: | ||||
return [d.name for d in existing] | return [d.name for d in existing] | ||||