diff --git a/addons/website/controllers/form.py b/addons/website/controllers/form.py
index a2d1a00212b..00f6ed05b44 100644
--- a/addons/website/controllers/form.py
+++ b/addons/website/controllers/form.py
@@ -232,7 +232,6 @@ class WebsiteForm(http.Controller):
record = request.env[model_name].with_user(SUPERUSER_ID).with_context(
mail_create_nosubscribe=True,
).create(values)
-
if custom or meta:
_custom_label = "%s\n___________\n\n" % _("Other Information:") # Title for custom fields
if model_name == 'mail.mail':
@@ -247,7 +246,7 @@ class WebsiteForm(http.Controller):
# If there isn't, put the custom data in a message instead
if default_field.name:
if default_field.ttype == 'html' or model_name == 'mail.mail':
- custom_content = nl2br(custom_content)
+ custom_content = nl2br_enclose(custom_content)
record.update({default_field.name: custom_content})
elif hasattr(record, '_message_log'):
record._message_log(
diff --git a/addons/website/tests/test_website_form_editor.py b/addons/website/tests/test_website_form_editor.py
index b807e0b1b62..2df90e51856 100644
--- a/addons/website/tests/test_website_form_editor.py
+++ b/addons/website/tests/test_website_form_editor.py
@@ -1,11 +1,14 @@
# Part of Odoo. See LICENSE file for full copyright and licensing details.
# -*- coding: utf-8 -*-
-import odoo.tests
+from odoo.http import request
from odoo.addons.base.tests.common import HttpCaseWithUserPortal
+from odoo.addons.website.controllers.form import WebsiteForm
+from odoo.addons.website.tools import MockRequest
+from odoo.tests.common import tagged, TransactionCase
-@odoo.tests.tagged('post_install', '-at_install')
+@tagged('post_install', '-at_install')
class TestWebsiteFormEditor(HttpCaseWithUserPortal):
@classmethod
def setUpClass(cls):
@@ -50,3 +53,21 @@ class TestWebsiteFormEditor(HttpCaseWithUserPortal):
self.start_tour('/contactus', 'website_form_contactus_change_random_option', login="admin")
self.env.company.email = 'after.change@mail.com'
self.start_tour('/contactus', 'website_form_contactus_check_changed_email', login="portal")
+
+
+@tagged('post_install', '-at_install')
+class TestWebsiteForm(TransactionCase):
+
+ def test_website_form_html_escaping(self):
+ website = self.env['website'].browse(1)
+ WebsiteFormController = WebsiteForm()
+ with MockRequest(self.env, website=website):
+ WebsiteFormController.insert_record(
+ request,
+ self.env['ir.model'].search([('model', '=', 'mail.mail')]),
+ {'email_from': 'odoobot@example.com', 'subject': 'John Smith', 'email_to': 'company@company.company'},
+ "John Smith",
+ )
+ mail = self.env['mail.mail'].search([], order='id desc', limit=1)
+ self.assertNotIn('', mail.body_html, "HTML should be escaped in website form")
+ self.assertIn('<b>', mail.body_html, "HTML should be escaped in website form (2)")