[FIX] mail: sent messages are plaintext

The problem was that users couldn't write characters like <, > in their
messages because the messages are html (e.g. '3 < 5' resulted in '3' because
this wasn't html valid so the second part was trimmed).

Because of mentions, we can't force messages to be plaintext (mentions are
processed and replaced by html links before the message is stored in DB).

The solution is to escape them just before processing the mentions. In the case
of chat windows, we must be careful because chat windows are also used for the
livechat, for which messages are plaintext. So the escaping should be done for
chat windows in the backend, but not in the livechat.
This commit is contained in:
Aaron Bohy
2015-12-16 15:48:42 +01:00
parent f5e4fbb20c
commit 2b99a36921
2 changed files with 2 additions and 1 deletions
+1 -1
View File
@@ -398,7 +398,7 @@ var Composer = Widget.extend({
preprocess_message: function () {
// Return a deferred as this function is extended with asynchronous
// behavior for the chatter composer
var value = this.$input.val().replace(/\n|\r/g, '<br/>');
var value = _.escape(this.$input.val()).replace(/\n|\r/g, '<br/>');
return $.when({
content: this.mention_manager.generate_links(value),
attachment_ids: _.pluck(this.get('attachment_ids'), 'id'),
@@ -38,6 +38,7 @@ function open_chat (session) {
});
chat_session.window.on("post_message", null, function (message, channel_id) {
message.content = _.escape(message.content);
chat_manager.post_message(message, {channel_id: channel_id});
});
chat_session.window.on("messages_read", null, function () {