Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: restrict method for security critical endpoints #25105

Merged
merged 1 commit into from Feb 27, 2024

Conversation

ankush
Copy link
Member

@ankush ankush commented Feb 27, 2024

No description provided.

@ankush ankush requested a review from a team as a code owner February 27, 2024 15:45
@ankush ankush requested review from akhilnarang and removed request for a team February 27, 2024 15:45
@ankush ankush enabled auto-merge (squash) February 27, 2024 15:45
@github-actions github-actions bot added the add-test-cases Add test case to validate fix or enhancement label Feb 27, 2024
@ankush ankush added backport version-14-hotfix backport to version 14 backport version-15-hotfix Backport the PR to v15 and removed add-test-cases Add test case to validate fix or enhancement labels Feb 27, 2024
@ankush ankush merged commit 01d2928 into frappe:develop Feb 27, 2024
23 checks passed
@ankush ankush deleted the set_method branch February 27, 2024 16:10
mergify bot pushed a commit that referenced this pull request Feb 27, 2024
(cherry picked from commit 01d2928)

# Conflicts:
#	frappe/core/doctype/user/user.py
mergify bot pushed a commit that referenced this pull request Feb 27, 2024
ankush added a commit that referenced this pull request Feb 27, 2024
(cherry picked from commit 01d2928)

Co-authored-by: Ankush Menat <ankush@frappe.io>
frappe-pr-bot pushed a commit that referenced this pull request Feb 28, 2024
# [15.16.0](v15.15.0...v15.16.0) (2024-02-28)

### Bug Fixes

* **a11y:** Improve desk accessibility (backport [#23319](#23319)) ([#25023](#25023)) ([48665e6](48665e6))
* add context for row number label ([235f921](235f921))
* add show_dashboard field on custom fields ([#24984](#24984)) ([#24986](#24986)) ([34bca99](34bca99))
* added important to bold class. ([718973e](718973e))
* allow negative numbers in grid search ([#24989](#24989)) ([#24991](#24991)) ([e778fe9](e778fe9))
* Avoid add "null" to cc in communication in timeline (backport [#25092](#25092)) ([#25096](#25096)) ([06c7a87](06c7a87))
* Cast to string to handle int PK ([#24988](#24988)) ([#24993](#24993)) ([de3042b](de3042b))
* Check perm for library file before cloning ([#25117](#25117)) ([#25120](#25120)) ([173ff30](173ff30))
* **ControlTime:** Don't set datepicker's date if field is read only ([#25038](#25038)) ([#25076](#25076)) ([3e33ae3](3e33ae3))
* Correct type hint ([#24990](#24990)) ([#24995](#24995)) ([3f956c1](3f956c1))
* disable internal columns like _comments from report column selec… ([#24998](#24998)) ([#25000](#25000)) ([76a32f2](76a32f2))
* Don't init site if already init-ed during truncate ([#25033](#25033)) ([#25036](#25036)) ([5ddbfb2](5ddbfb2))
* **File Uploader:** call 'upload_files' without passing event object ([#25034](#25034)) ([#25087](#25087)) ([ce5abfc](ce5abfc))
* force `[]` as default for child tables ([#24000](#24000)) ([fea1623](fea1623))
* **formatters:** Translate Select value in format_value ([#24951](#24951)) ([#25077](#25077)) ([ff9e199](ff9e199))
* german translation of No. ([4e491b2](4e491b2))
* grid row default values not using model (backport [#23701](#23701)) ([#24896](#24896)) ([ad05acb](ad05acb))
* **grid:** Add type attribute to buttons ([#25021](#25021)) ([#25022](#25022)) ([d440fef](d440fef))
* Guess currency from report row if available ([#25009](#25009)) ([#25010](#25010)) ([dfcee61](dfcee61))
* handle total rows in number card ([#25011](#25011)) ([#25012](#25012)) ([4882bfc](4882bfc))
* invalid lru_cache usage ([#25046](#25046)) ([#25047](#25047)) ([e275851](e275851))
* **module_map:** only include apps installed on the site - not everything on the bench (backport [#24688](#24688)) ([#25122](#25122)) ([79e7c57](79e7c57))
* Private images in PDFs from background jobs ([#24980](#24980)) ([#25015](#25015)) ([3211ccf](3211ccf))
* replaced created by with owner in base_document ([#25059](#25059)) ([#25061](#25061)) ([bc5d09d](bc5d09d))
* restrict method for security critical endpoints ([#25105](#25105)) ([#25108](#25108)) ([44f4858](44f4858))
* ruff fixes ([c557ec6](c557ec6))
* show tooltip on edit table row (backport [#25040](#25040)) ([#25069](#25069)) ([2afbed7](2afbed7))
* spelling of "recording" in button (backport [#25025](#25025)) ([#25026](#25026)) ([6bf4f1c](6bf4f1c))
* support running QB union queries (backport [#24757](#24757)) ([#25016](#25016)) ([c092efa](c092efa))
* translate doctype in user-facing error message ([#25045](#25045)) ([3cd1eb2](3cd1eb2))
* validate fetch from ([#25116](#25116)) ([#25118](#25118)) ([624985d](624985d))
* wrap read_only functions correctly ([#25018](#25018)) ([#25020](#25020)) ([88a09be](88a09be))

### Features

* add push notification ([93ecd40](93ecd40))
* hook for print format template loader ([#25037](#25037)) ([#25074](#25074)) ([201e30f](201e30f))
* Impersonate a user (backport [#25050](#25050)) ([#25051](#25051)) ([813fb59](813fb59))
* socketio using authorization headers (backport [#24858](#24858)) ([#24966](#24966)) ([2045340](2045340))
* support array request type ([#25109](#25109)) ([#25112](#25112)) ([957d3eb](957d3eb))

### Performance Improvements

* avoid unnecessary json parsing ([#25065](#25065)) ([#25073](#25073)) ([1b814b3](1b814b3))
* don't process checks if there are none ([#25063](#25063)) ([#25071](#25071)) ([c3b0931](c3b0931))
* remove specific elements instead of re-rendering entire list ([#25078](#25078)) ([#25089](#25089)) ([37c9d3f](37c9d3f))
ankush added a commit that referenced this pull request Mar 4, 2024
#25107)

* fix: restrict method for security critical endpoints (#25105)

(cherry picked from commit 01d2928)

# Conflicts:
#	frappe/core/doctype/user/user.py

* chore: conflicts

---------

Co-authored-by: Ankush Menat <ankush@frappe.io>
frappe-pr-bot pushed a commit that referenced this pull request Mar 5, 2024
# [14.67.0](v14.66.3...v14.67.0) (2024-03-05)

### Bug Fixes

* add "If Owner" column to roles viewer ([#25218](#25218)) ([#25219](#25219)) ([51db516](51db516))
* always show is_standard on web form ([#25144](#25144)) ([#25147](#25147)) ([92ea2e7](92ea2e7))
* dont get message attribute in error string in  has_login_limit_exceeded ([#25165](#25165)) ([ae07a32](ae07a32))
* dont translate numbers ([#25208](#25208)) ([#25209](#25209)) ([9a7b217](9a7b217))
* escape single quotes ([#25104](#25104)) ([#25153](#25153)) ([37bd2ad](37bd2ad)), closes [/github.com//pull/25078#discussion_r1504084483](https://github.com//github.com/frappe/frappe/pull/25078/issues/discussion_r1504084483)
* restrict method for security critical endpoints (backport [#25105](#25105)) ([#25107](#25107)) ([3b34ca6](3b34ca6))
* **search:** Don't break when query doesn't return title ([#25168](#25168)) ([#25196](#25196)) ([2718373](2718373))
* update file attached_to details in submitted doc ([#25140](#25140)) ([f116cdc](f116cdc))
* Use current language in attachment prints ([0e32b42](0e32b42))
* use name for RQ worker instead of PID (backport [#25175](#25175)) ([#25176](#25176)) ([359b103](359b103))
* **UX:** correctly disable standard web form form ([#25143](#25143)) ([#25145](#25145)) ([95f5dde](95f5dde))
* **UX:** list filter take zero as null ([#25156](#25156)) ([#25221](#25221)) ([d04607a](d04607a))
* **UX:** reload form after renaming field (backport [#25159](#25159)) ([#25160](#25160)) ([6c7b4cd](6c7b4cd))

### Features

* basic tracing using monitor trace id (backport [#22126](#22126)) ([#25216](#25216)) ([59791dc](59791dc))
* Skip locked rows while selecting + fix delete race condition (backport [#24298](#24298) and [#25170](#25170)) ([#25169](#25169)) ([1119bfd](1119bfd))
* track skipped patch with traceback (backport [#20931](#20931)) ([#25214](#25214)) ([f50b53d](f50b53d))
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Mar 13, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
backport version-14-hotfix backport to version 14 backport version-15-hotfix Backport the PR to v15
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant