From 33ed16490ece9ba4f51557a315faab9470ac06ad Mon Sep 17 00:00:00 2001 From: Romain Derie Date: Fri, 7 Jul 2023 10:28:30 +0000 Subject: [PATCH] [FIX] sale_quotation_builder: add sanitize overridable Step to reproduce: - Be sure to have `sale_quotation_builder` installed - Drag & drop the "Steps" snippet on a product in edit mode - Add this product on a SO in the backend - Click on Customer Preview -> The step snippet will not have the connector lines anymore This is because in Odoo 16, the step snippet connectors are now `svg` element (see [1]) which are removed by the sanitizer. ```py from lxml.html import clean svg='' clean.Cleaner().clean_html(svg) ``` It's not the case in the `website_description` field of the product template as this field is defined with `sanitize_overridable=True` [2] which make it so the users with the right to do so can bypass the sanitation and use the Step snippet in this field. Since the quotation description can be a copy of that field, but without the same sanitize behavior, the connectors are lost. Note that most of the `sale_quotation_builder` description HTML fields were already set as `sanitize_overridable=True` with [2] and [3] but those ones were not. [1]: https://github.com/odoo/odoo/commit/aba31e9f2d8a44ce1586403f2a621a6caeed57b4 [2]: https://github.com/odoo/odoo/commit/44ae3f38da07c2215b1547d992f053a11829a8ac [3]: https://github.com/odoo/odoo/commit/811cf78ee1e63a7c41efe578fb64ee2deeca1dde opw-3380346 closes odoo/odoo#129690 X-original-commit: 7a928c92136400454e7ed53326f2cdc9173fa1b3 Signed-off-by: Romain Derie (rde) --- addons/sale_quotation_builder/models/product_template.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/addons/sale_quotation_builder/models/product_template.py b/addons/sale_quotation_builder/models/product_template.py index 7d7a90e8517..ad642f85bde 100644 --- a/addons/sale_quotation_builder/models/product_template.py +++ b/addons/sale_quotation_builder/models/product_template.py @@ -12,14 +12,16 @@ class ProductTemplate(models.Model): string="Quotation Only Description", translate=html_translate, sanitize_attributes=False, + sanitize_overridable=True, help="The quotation description (not used on eCommerce)") quotation_description = fields.Html( string="Quotation Description", compute='_compute_quotation_description', sanitize_attributes=False, + sanitize_overridable=True, help="This field uses the Quotation Only Description if it is defined, " - "otherwise it will try to read the eCommerce Description.") + "otherwise it will try to read the eCommerce Description.") def _compute_quotation_description(self): for template in self: