06/01 Review and optimize on UI/UX, security, and functionality
This commit is contained in:
@@ -398,4 +398,5 @@ def delete_receipt(txn_id):
|
||||
@login_required
|
||||
def view_receipt(filename):
|
||||
upload_dir = current_app.config.get('UPLOAD_FOLDER', '/home/pfm/app/uploads')
|
||||
return send_from_directory(upload_dir, filename)
|
||||
# Strip any path components to prevent directory traversal
|
||||
return send_from_directory(upload_dir, os.path.basename(filename))
|
||||
|
||||
@@ -128,7 +128,10 @@ def map_accounts(enrollment_id):
|
||||
db.session.flush()
|
||||
ta.pfm_account_id = new_acct.id
|
||||
elif val.isdigit():
|
||||
ta.pfm_account_id = int(val)
|
||||
acct_id = int(val)
|
||||
# Verify the account actually exists and belongs to this app
|
||||
if Account.query.filter_by(id=acct_id, is_active=True).first():
|
||||
ta.pfm_account_id = acct_id
|
||||
# val == '' means skip this account
|
||||
db.session.commit()
|
||||
|
||||
|
||||
@@ -69,10 +69,13 @@ def index():
|
||||
|
||||
if search:
|
||||
query = query.filter(Transaction.description.ilike(f'%{search}%'))
|
||||
if category_id:
|
||||
query = query.filter(Transaction.category_id == int(category_id))
|
||||
if account_id:
|
||||
query = query.filter(Transaction.account_id == int(account_id))
|
||||
try:
|
||||
if category_id:
|
||||
query = query.filter(Transaction.category_id == int(category_id))
|
||||
if account_id:
|
||||
query = query.filter(Transaction.account_id == int(account_id))
|
||||
except (ValueError, TypeError):
|
||||
pass
|
||||
if date_from:
|
||||
try:
|
||||
query = query.filter(Transaction.date >= datetime.strptime(date_from, '%Y-%m-%d').date())
|
||||
|
||||
Reference in New Issue
Block a user