[FIX] web: prevent crash when searching for escaped strings

Recent works in the search view (in 12.0) on dynamic filters had an
unfortunate effect: when the user tries to input escaped strings (for
example "test" in custom filters, there was a crash.

The reason is that the JS python parser (or more specifically, the
tokenizer) was unable to parse that as a string.  It worked before
because the web client sent the raw string to the server.  However, with
dynamic filters, this is no longer the case, and we need to parse
domains to be able to combine them.

In this commit, we modify the tokenizer to be able to work with escaped
strings.

closes odoo/odoo#29324
This commit is contained in:
Géry Debongnie
2018-12-06 15:16:32 +00:00
parent 84b976fb7c
commit 6d3ada178f
2 changed files with 16 additions and 3 deletions
+9 -3
View File
@@ -282,7 +282,10 @@ var py = {};
var name_pattern = new RegExp('^' + Name + '$');
var strip = new RegExp('^' + Whitespace);
return function tokenize(s) {
var max=s.length, tokens = [], start, end = undefined;
s = s
.replace(/\\\"/g, '\\u0022') // for double quote
.replace(/\\\'/g, '\\u0027'); // for single quote
var max=s.length, tokens = [], start, end;
// /g flag makes repeated exec() have memory
var pseudoprog = new RegExp(PseudoToken, 'g');
@@ -302,7 +305,6 @@ var py = {};
end = pseudoprog.lastIndex;
// strip leading space caught by Whitespace
var token = s.slice(start, end).replace(strip, '');
var initial = token[0];
if (number_pattern.test(token)) {
tokens.push(create(symbols['(number)'], {
@@ -310,9 +312,13 @@ var py = {};
}));
} else if (string_pattern.test(token)) {
var m = string_pattern.exec(token);
var value = (m[3] !== undefined ? m[3] : m[5]);
value
.replace(/\\u0022/g, '"')
.replace(/\\u0027/g, "'");
tokens.push(create(symbols['(string)'], {
unicode: !!(m[2] || m[4]),
value: (m[3] !== undefined ? m[3] : m[5])
value: value
}));
} else if (token in symbols) {
var symbol;
@@ -1254,6 +1254,13 @@ QUnit.module('core', function () {
assert.checkAST(expr);
});
QUnit.test("parse escaped quoted strings", function (assert) {
assert.expect(2);
assert.checkAST(`'\"'`, "a string containing \"");
assert.checkAST(`'\'`, "a string containing \'");
});
QUnit.module('pyutils (_normalizeDomain)');
QUnit.assert.checkNormalization = function (domain, normalizedDomain) {