Remove escaped customer string (#13986)
- no need to escape strings that are passed to the values parameter of the sql method - this query was failing for inputs like "D'Arby" which have quotes
This commit is contained in:
parent
9d215c2d9b
commit
f2b3307136
@ -316,7 +316,7 @@ def make_address(args, is_primary_address=1):
|
||||
return address
|
||||
|
||||
def get_customer_primary_contact(doctype, txt, searchfield, start, page_len, filters):
|
||||
customer = frappe.db.escape(filters.get('customer'))
|
||||
customer = filters.get('customer')
|
||||
return frappe.db.sql("""
|
||||
select `tabContact`.name from `tabContact`, `tabDynamic Link`
|
||||
where `tabContact`.name = `tabDynamic Link`.parent and `tabDynamic Link`.link_name = %(customer)s
|
||||
|
Loading…
Reference in New Issue
Block a user