seitime-frappe/frappe
Chinmay D. Pai 2ea74dee36
fix: check for whitelist before calling from search
search widget takes query as an input, but does not check whether the
query function that is called is whitelisted, basically allowing anyone
logged-in to call any function regardless of the whitelist.

Signed-off-by: Chinmay D. Pai <chinmaydpai@gmail.com>
2020-05-26 18:47:17 +05:30
..
automation Merge pull request #9957 from hrwX/multiple_assignments 2020-05-18 18:26:12 +05:30
change_log fix: more url fixes 2019-07-24 16:09:56 +05:30
chat chore: fix indentation and cleanup annoying spaces 2019-12-27 13:24:59 +05:30
commands fix: run cleanup only after new-site 2020-05-26 11:20:25 +05:30
config feat: rename to package 2020-04-29 10:31:28 +05:30
contacts fix: TypeError in cmp 2020-05-16 20:08:38 +05:30
core style: Fix cider 2020-05-26 10:03:13 +05:30
custom Merge pull request #9692 from hrwX/cust_export 2020-05-15 12:36:24 +00:00
data
data_migration Undefined name: e in data_migration_run.py 2019-11-02 13:12:45 +01:00
database feat: Section Break without border 2020-05-15 10:11:58 +05:30
desk fix: check for whitelist before calling from search 2020-05-26 18:47:17 +05:30
email perf: Make tests faster (#10307) 2020-05-12 22:34:10 +05:30
event_streaming fix: failing test 2020-04-30 18:36:07 +05:30
geo fix: Update country.json 2020-02-24 15:46:39 +05:30
integrations chore: add missed import 2020-05-15 17:52:40 +05:30
model Wrappe frappe._dict 2020-05-21 18:47:00 +08:00
modules refactor: rename onboarding to module onboarding 2020-05-12 16:23:26 +05:30
patches Merge pull request #10232 from scmmishra/web-analytics-report 2020-05-22 04:51:25 +00:00
printing style: linting fixes for deepsource 2020-05-01 12:12:56 +05:30
public Merge pull request #10467 from prssanna/chart-report-filters 2020-05-25 16:06:28 +00:00
social fix: test cases 2020-05-18 12:54:26 +05:30
templates Merge branch 'develop' into develop-reports-print-format 2020-05-22 10:31:23 +05:30
tests Merge branch 'develop' of https://github.com/frappe/frappe into multiple_assignments 2020-05-15 15:21:05 +05:30
translations fix: Contextual translation key generation 2020-05-04 22:27:06 +05:30
utils fix: backwards compatible verbose flag 2020-05-22 12:12:14 +05:30
website Merge pull request #10232 from scmmishra/web-analytics-report 2020-05-22 04:51:25 +00:00
workflow refactor: Commonify transition condition evaluation 2020-03-24 13:28:30 +05:30
www Merge pull request #10232 from scmmishra/web-analytics-report 2020-05-22 04:51:25 +00:00
__init__.py perf: Make tests faster (#10307) 2020-05-12 22:34:10 +05:30
api.py fix(api): Fix api for user oauth validations (#9676) 2020-04-11 10:27:00 +05:30
app.py feat(rate-limiter): Ignore requests above limit 2020-05-13 12:34:07 +05:30
auth.py fix: no need for password check 2020-04-19 15:58:29 +02:00
boot.py fix: use get-all instead of get-list (#10444) 2020-05-21 17:06:45 +05:30
build.py refactor: updated variable name + style fixes 2020-01-04 10:53:53 +05:30
cache_manager.py perf(desk): Even faster desk (#9930) 2020-05-13 15:12:19 +00:00
client.py fix(translations): Incorrect syntax 2020-01-29 15:22:35 +05:30
defaults.py
deferred_insert.py
exceptions.py feat(rate-limiter): Ignore requests above limit 2020-05-13 12:34:07 +05:30
frappeclient.py fix: Better error handling in FrappeClient login 2020-05-13 05:45:38 +05:30
handler.py refactor: translate error message 2020-04-30 15:56:34 +05:30
hooks.py Merge branch 'develop' into contextual-translation 2020-05-01 15:40:48 +05:30
installer.py fix: Add db-password option to new-site (#9685) 2020-03-13 15:10:59 +05:30
middlewares.py chore: update werkzeug to 1.0.0 2020-02-07 12:16:42 +05:30
migrate.py Merge pull request #10293 from gavindsouza/installed-apps 2020-05-14 23:55:16 +00:00
modules.txt fix: rename Events Streaming to Event Streaming 2019-12-26 14:29:08 +05:30
monitor.py feat(rate-limiter): Log data with monitor 2020-05-13 12:34:07 +05:30
oauth.py
patches.txt feat: patch to delete onboarding slide doctype 2020-05-26 12:30:29 +05:30
permissions.py fix: only encode if type is not str 2020-03-31 16:23:12 +05:30
pythonrc.py
rate_limiter.py fix(rate-limiter): Remove duplicate headers 2020-05-13 13:45:55 +05:30
realtime.py
recorder.py style: Black + Flake8 2020-05-08 15:35:53 +05:30
sessions.py fix: clear_sessions should by default include mobile 2020-05-06 14:21:44 +05:30
share.py fix(translations): Incorrect syntax 2020-01-29 15:22:35 +05:30
test_runner.py Merge remote-tracking branch 'origin/develop' into ci/reports 2019-12-14 14:38:43 +01:00
translate.py fix: Contextual translation key generation 2020-05-04 22:27:06 +05:30
twofactor.py fix: case where background task had no IP 2020-04-30 07:28:04 +00:00