Compare commits

...

1 Commits

Author SHA1 Message Date
Anand Doshi
62d1256d44 [fix] injection 2015-12-01 17:02:04 +05:30
2 changed files with 8 additions and 8 deletions

View File

@@ -26,9 +26,9 @@ def get_children():
acc = frappe.db.sql(""" select acc = frappe.db.sql(""" select
name as value, is_group as expandable %s name as value, is_group as expandable %s
from `tab%s` from `tab%s`
where ifnull(parent_%s,'') = '' where ifnull(`parent_%s`,'') = ''
and `company` = %s and docstatus<2 and `company` = %s and docstatus<2
order by name""" % (select_cond, ctype, ctype.lower().replace(' ','_'), '%s'), order by name""" % (select_cond, frappe.db.escape(ctype), frappe.db.escape(ctype.lower().replace(' ','_')), '%s'),
company, as_dict=1) company, as_dict=1)
if args["parent"]=="Accounts": if args["parent"]=="Accounts":
@@ -38,9 +38,9 @@ def get_children():
acc = frappe.db.sql("""select acc = frappe.db.sql("""select
name as value, is_group as expandable name as value, is_group as expandable
from `tab%s` from `tab%s`
where ifnull(parent_%s,'') = %s where ifnull(`parent_%s`,'') = %s
and docstatus<2 and docstatus<2
order by name""" % (ctype, ctype.lower().replace(' ','_'), '%s'), order by name""" % (frappe.db.escape(ctype), frappe.db.escape(ctype.lower().replace(' ','_')), '%s'),
args['parent'], as_dict=1) args['parent'], as_dict=1)
if ctype == 'Account': if ctype == 'Account':

View File

@@ -62,7 +62,7 @@ def get_balance_on(account=None, date=None, party_type=None, party=None):
cond = [] cond = []
if date: if date:
cond.append("posting_date <= '%s'" % date) cond.append("posting_date <= '%s'" % frappe.db.escape(date))
else: else:
# get balance of all entries that exist # get balance of all entries that exist
date = nowdate() date = nowdate()
@@ -95,11 +95,11 @@ def get_balance_on(account=None, date=None, party_type=None, party=None):
and ac.lft >= %s and ac.rgt <= %s and ac.lft >= %s and ac.rgt <= %s
)""" % (acc.lft, acc.rgt)) )""" % (acc.lft, acc.rgt))
else: else:
cond.append("""gle.account = "%s" """ % (account.replace('"', '\\"'), )) cond.append("""gle.account = "%s" """ % (frappe.db.escape(account),))
if party_type and party: if party_type and party:
cond.append("""gle.party_type = "%s" and gle.party = "%s" """ % cond.append("""gle.party_type = "%s" and gle.party = "%s" """ %
(party_type.replace('"', '\\"'), party.replace('"', '\\"'))) (frappe.db.escape(party_type), frappe.db.escape(party)))
if account or (party_type and party): if account or (party_type and party):
bal = frappe.db.sql(""" bal = frappe.db.sql("""