Minor fixes: escaped characters
This commit is contained in:
parent
b301603740
commit
fe93ea56b6
@ -27,7 +27,7 @@ def get_permission_query_conditions(user):
|
||||
return """(`tabNote`.public=1 or `tabNote`.owner="{user}" or exists (
|
||||
select name from `tabNote User`
|
||||
where `tabNote User`.parent=`tabNote`.name
|
||||
and `tabNote User`.user="{user}"))""".format(user=user)
|
||||
and `tabNote User`.user="{user}"))""".format(user=frappe,db.escape(user))
|
||||
|
||||
def has_permission(doc, ptype, user):
|
||||
if doc.public == 1 or user == "Administrator":
|
||||
|
Loading…
Reference in New Issue
Block a user