diff --git a/addons/website/controllers/form.py b/addons/website/controllers/form.py index a2d1a00212b..00f6ed05b44 100644 --- a/addons/website/controllers/form.py +++ b/addons/website/controllers/form.py @@ -232,7 +232,6 @@ class WebsiteForm(http.Controller): record = request.env[model_name].with_user(SUPERUSER_ID).with_context( mail_create_nosubscribe=True, ).create(values) - if custom or meta: _custom_label = "%s\n___________\n\n" % _("Other Information:") # Title for custom fields if model_name == 'mail.mail': @@ -247,7 +246,7 @@ class WebsiteForm(http.Controller): # If there isn't, put the custom data in a message instead if default_field.name: if default_field.ttype == 'html' or model_name == 'mail.mail': - custom_content = nl2br(custom_content) + custom_content = nl2br_enclose(custom_content) record.update({default_field.name: custom_content}) elif hasattr(record, '_message_log'): record._message_log( diff --git a/addons/website/tests/test_website_form_editor.py b/addons/website/tests/test_website_form_editor.py index b807e0b1b62..2df90e51856 100644 --- a/addons/website/tests/test_website_form_editor.py +++ b/addons/website/tests/test_website_form_editor.py @@ -1,11 +1,14 @@ # Part of Odoo. See LICENSE file for full copyright and licensing details. # -*- coding: utf-8 -*- -import odoo.tests +from odoo.http import request from odoo.addons.base.tests.common import HttpCaseWithUserPortal +from odoo.addons.website.controllers.form import WebsiteForm +from odoo.addons.website.tools import MockRequest +from odoo.tests.common import tagged, TransactionCase -@odoo.tests.tagged('post_install', '-at_install') +@tagged('post_install', '-at_install') class TestWebsiteFormEditor(HttpCaseWithUserPortal): @classmethod def setUpClass(cls): @@ -50,3 +53,21 @@ class TestWebsiteFormEditor(HttpCaseWithUserPortal): self.start_tour('/contactus', 'website_form_contactus_change_random_option', login="admin") self.env.company.email = 'after.change@mail.com' self.start_tour('/contactus', 'website_form_contactus_check_changed_email', login="portal") + + +@tagged('post_install', '-at_install') +class TestWebsiteForm(TransactionCase): + + def test_website_form_html_escaping(self): + website = self.env['website'].browse(1) + WebsiteFormController = WebsiteForm() + with MockRequest(self.env, website=website): + WebsiteFormController.insert_record( + request, + self.env['ir.model'].search([('model', '=', 'mail.mail')]), + {'email_from': 'odoobot@example.com', 'subject': 'John Smith', 'email_to': 'company@company.company'}, + "John Smith", + ) + mail = self.env['mail.mail'].search([], order='id desc', limit=1) + self.assertNotIn('', mail.body_html, "HTML should be escaped in website form") + self.assertIn('<b>', mail.body_html, "HTML should be escaped in website form (2)")