fix(patch): escape illegal characters to avoid SQL syntax error (#17890)
This commit is contained in:
parent
b9102bba48
commit
3720126ee9
@ -40,7 +40,7 @@ def execute():
|
|||||||
# This is probably never used anywhere else as of now, but should be
|
# This is probably never used anywhere else as of now, but should be
|
||||||
values = []
|
values = []
|
||||||
for d in batch_transactions:
|
for d in batch_transactions:
|
||||||
values.append("('{}', {})".format(d.parent, d.qty))
|
values.append("('{}', {})".format(frappe.db.escape(d.parent), d.qty))
|
||||||
conditions = ",".join(values)
|
conditions = ",".join(values)
|
||||||
frappe.db.sql("""
|
frappe.db.sql("""
|
||||||
INSERT INTO `tab{}` (name, total_qty) VALUES {}
|
INSERT INTO `tab{}` (name, total_qty) VALUES {}
|
||||||
|
Loading…
Reference in New Issue
Block a user