From 2b99a36921171bd66eefae03d494d0fbf8618932 Mon Sep 17 00:00:00 2001 From: Aaron Bohy Date: Tue, 15 Dec 2015 11:03:35 +0100 Subject: [PATCH] [FIX] mail: sent messages are plaintext The problem was that users couldn't write characters like <, > in their messages because the messages are html (e.g. '3 < 5' resulted in '3' because this wasn't html valid so the second part was trimmed). Because of mentions, we can't force messages to be plaintext (mentions are processed and replaced by html links before the message is stored in DB). The solution is to escape them just before processing the mentions. In the case of chat windows, we must be careful because chat windows are also used for the livechat, for which messages are plaintext. So the escaping should be done for chat windows in the backend, but not in the livechat. --- addons/mail/static/src/js/composer.js | 2 +- addons/mail/static/src/js/window_manager.js | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/addons/mail/static/src/js/composer.js b/addons/mail/static/src/js/composer.js index 4112a8498cf..2965ccf9298 100644 --- a/addons/mail/static/src/js/composer.js +++ b/addons/mail/static/src/js/composer.js @@ -398,7 +398,7 @@ var Composer = Widget.extend({ preprocess_message: function () { // Return a deferred as this function is extended with asynchronous // behavior for the chatter composer - var value = this.$input.val().replace(/\n|\r/g, '
'); + var value = _.escape(this.$input.val()).replace(/\n|\r/g, '
'); return $.when({ content: this.mention_manager.generate_links(value), attachment_ids: _.pluck(this.get('attachment_ids'), 'id'), diff --git a/addons/mail/static/src/js/window_manager.js b/addons/mail/static/src/js/window_manager.js index fe60dff4bd5..f217d929c20 100644 --- a/addons/mail/static/src/js/window_manager.js +++ b/addons/mail/static/src/js/window_manager.js @@ -38,6 +38,7 @@ function open_chat (session) { }); chat_session.window.on("post_message", null, function (message, channel_id) { + message.content = _.escape(message.content); chat_manager.post_message(message, {channel_id: channel_id}); }); chat_session.window.on("messages_read", null, function () {