[FIX] sale_quotation_builder: add sanitize overridable

Step to reproduce:
- Be sure to have `sale_quotation_builder` installed
- Drag & drop the "Steps" snippet on a product in edit mode
- Add this product on a SO in the backend
- Click on Customer Preview
-> The step snippet will not have the connector lines anymore

This is because in Odoo 16, the step snippet connectors are now `svg`
element (see [1]) which are removed by the sanitizer.

```py
from lxml.html import clean
svg='<svg><path/></svg>'
clean.Cleaner().clean_html(svg)
```

It's not the case in the `website_description` field of the product
template as this field is defined with `sanitize_overridable=True` [2]
which make it so the users with the right to do so can bypass the
sanitation and use the Step snippet in this field.

Since the quotation description can be a copy of that field, but without
the same sanitize behavior, the connectors are lost.

Note that most of the `sale_quotation_builder` description HTML fields
were already set as `sanitize_overridable=True` with [2] and [3] but
those ones were not.

[1]: https://github.com/odoo/odoo/commit/aba31e9f2d8a44ce1586403f2a621a6caeed57b4
[2]: https://github.com/odoo/odoo/commit/44ae3f38da07c2215b1547d992f053a11829a8ac
[3]: https://github.com/odoo/odoo/commit/811cf78ee1e63a7c41efe578fb64ee2deeca1dde

opw-3380346

closes odoo/odoo#129690

X-original-commit: 7a928c92136400454e7ed53326f2cdc9173fa1b3
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
This commit is contained in:
Romain Derie
2023-07-26 12:00:30 +02:00
parent 234385a7b6
commit 33ed16490e
@@ -12,14 +12,16 @@ class ProductTemplate(models.Model):
string="Quotation Only Description",
translate=html_translate,
sanitize_attributes=False,
sanitize_overridable=True,
help="The quotation description (not used on eCommerce)")
quotation_description = fields.Html(
string="Quotation Description",
compute='_compute_quotation_description',
sanitize_attributes=False,
sanitize_overridable=True,
help="This field uses the Quotation Only Description if it is defined, "
"otherwise it will try to read the eCommerce Description.")
"otherwise it will try to read the eCommerce Description.")
def _compute_quotation_description(self):
for template in self: