Skip to content

feat: add role based permissions - #12

Merged
trufurs merged 6 commits into
developfrom
fix/add-permissions
Sep 22, 2026
Merged

trufurs merged 6 commits into
developfrom
fix/add-permissions

Conversation

@trufurs

@trufurs trufurs commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

This pull request introduces several improvements to the wordpress_form_apis package, focusing on enhanced security for lead-related API endpoints and improved error handling. The main changes include role-based access control for sensitive API methods and more user-friendly error messages.

Security and Access Control:

  • Added an ALLOWED_ROLES list (containing "Gravity Form") and enforced role-based access using frappe.only_for(ALLOWED_ROLES) in the upload_lead_file, get_lead_sources, and _filter_payload functions to ensure only authorized roles can access these endpoints. [1] [2]

Error Handling Improvements:

  • Updated the error response in the create function to return a generic error message instead of the raw exception, and added frappe.clear_messages() to clear any previous messages.

Version Update:

  • Bumped the package version from 1.0.1 to 1.0.2 in __init__.py to reflect these changes.

@trufurs
trufurs requested a review from dpk404 September 21, 2026 06:47
Comment thread wordpress_form_apis/api/crm_lead.py Outdated
@trufurs
trufurs requested a review from dpk404 September 21, 2026 07:32
@trufurs
trufurs merged commit 6ac103a into develop Sep 22, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants