[fix] escape quote in Accounts Receivable

This commit is contained in:
Anand Doshi 2015-01-08 18:26:53 +05:30
parent 7620efc9ad
commit 015fa7a1d1

View File

@ -149,7 +149,7 @@ class AccountsReceivableReport(object):
if not account_map:
frappe.throw(_("No Customer Accounts found."))
else:
accounts_list = ['"{0}"'.format(ac.replace('"', '\"')) for ac in account_map]
accounts_list = ["'{0}'".format(frappe.db.escape(ac)) for ac in account_map]
conditions.append("account in ({0})".format(", ".join(accounts_list)))
return " and ".join(conditions), values