Senior Frappe Developer – Custom App & Security Hardening (Remote India / Fixed Budget)

About the Project: We are a premium luxury menswear brand (Bespoke Loft) deploying a self-hosted Frappe/ERPNext instance. We are looking for a senior, independent Frappe Developer (India-based) to build a lean, custom app during a focused 14-day sprint.

We want a clean, isolated custom app deployment with zero modifications to the ERPNext core. Agencies will not be considered; we are looking for a dedicated independent engineer.

Core Deliverables & Scope:

  1. Custom Measurement Vault:

    • Build a custom DocType to store detailed physical client measurements.

    • Must include version control/history tracking so previous measurement adjustments are never overwritten.

  2. Multi-Stage Trial Lifecycle Workflow:

    • Custom workflow tracking garments through multiple physical trial and fitting stages (e.g., Pattern Draft, Basted Fitting, Final Tweak, Delivered).

    • Automated status transitions and limited user field-level editing permissions based on workflow state.

  3. Data Loss Prevention (DLP) & Security Hardening:

    • Absolute Export Ban: Completely disable data export functionalities (CSV, Excel) across the custom DocTypes for non-admin roles.

    • Strict restriction of PDF/Print format rendering to authorized roles only.

    • Hardening permissions at the framework level (hooks.py overrides / server-side whitelisting blocks) to prevent frontend API data scraping.

Technical Stack Requirements:

  • Framework: Frappe Framework v15 / ERPNext v15

  • Backend: Python, MariaDB

  • Frontend: JavaScript / Frappe Desk UI

  • Deployment: Self-hosted (Ubuntu / Docker)

Engagement Terms:

  • Timeline: 14-day sprint from kickoff to deployment.

  • Budget: Fixed budget (milestone-based).

  • Location: Remote (Must be aligned with India Standard Time for communication).

How to Apply:

If you are interested, please reply to this post or DM with:

  1. A brief summary of your Frappe/ERPNext experience.

  2. Link to your public GitHub profile or examples of custom Frappe apps you have built.

  3. A quick 1-sentence answer on your technical approach: How would you reliably block the standard “Export” button/API route for a specific DocType at the server level via your custom app’s hooks.py?

1 Like

Hi @Siraj and welcome to the community

You can also post in Telegram: View @erpnextfreelancers for wider coverage

Hope it helps

Thank you for the warm welcome and the recommendation. I appreciate the lead on the Telegram group and will post our project requirements there to expand our search for a specialized Frappe developer.

Regards,

Siraj Mohiuddin

Hi Siraj,
Please connect with me for further discussion.

Jo

Hi Siraj,

I’m interested in this opportunity.

I have around 2 years of hands-on experience with the Frappe Framework and ERPNext, primarily building custom applications, HRMS customizations, custom DocTypes, workflows, role-based permissions, client/server scripts, REST APIs, reports, and self-hosted ERPNext deployments. I always prefer building clean, maintainable solutions without modifying the ERPNext core.

GitHub: https://github.com/karan200-max

Technical approach: I would block the standard Export functionality by overriding the export endpoints in hooks.py, enforcing server-side role and permission checks, and preventing unauthorized export API requests regardless of any frontend manipulation. Print/PDF access would also be restricted through role-based permission checks and server-side validation.

I’m available to work remotely in IST and can dedicate myself to the 14-day sprint. I’d be happy to discuss the project further.

Thanks,
Karan Barbade