[fix] consider optional fields too while chekcing sql injection
This commit is contained in:
parent
5f5d3066fa
commit
b2b2df56aa
1 changed files with 1 additions and 1 deletions
|
|
@ -493,7 +493,7 @@ class DatabaseQuery(object):
|
|||
frappe.throw(_("Please select atleast 1 column from {0} to sort/group").format(tbl))
|
||||
else:
|
||||
field = field.strip().split(' ')[0]
|
||||
if field not in [f.fieldname for f in meta.fields] and field not in default_fields:
|
||||
if field not in [f.fieldname for f in meta.fields] and field not in (default_fields + optional_fields):
|
||||
frappe.throw(_("Invalid field used to sort/group: {0}").format(field))
|
||||
|
||||
def add_limit(self):
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue