From 9ae4100836b9b43b242a1a71c8a6cbb7d659419b Mon Sep 17 00:00:00 2001 From: Suraj Shetty Date: Mon, 12 Aug 2019 21:25:37 +0530 Subject: [PATCH] fix(security): fix(security): Remove 'ignore_permissions' from in form_dict --- frappe/desk/reportview.py | 1 + 1 file changed, 1 insertion(+) diff --git a/frappe/desk/reportview.py b/frappe/desk/reportview.py index 226dab5c5b..87f2b01dfb 100644 --- a/frappe/desk/reportview.py +++ b/frappe/desk/reportview.py @@ -30,6 +30,7 @@ def get_form_params(): data.pop('cmd', None) data.pop('data', None) + data.pop('ignore_permissions', None) if "csrf_token" in data: del data["csrf_token"]