From 6d3ada178f7caf6ea159b871648ca4c440c7845b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?G=C3=A9ry=20Debongnie?= Date: Thu, 6 Dec 2018 15:06:56 +0000 Subject: [PATCH] [FIX] web: prevent crash when searching for escaped strings Recent works in the search view (in 12.0) on dynamic filters had an unfortunate effect: when the user tries to input escaped strings (for example "test" in custom filters, there was a crash. The reason is that the JS python parser (or more specifically, the tokenizer) was unable to parse that as a string. It worked before because the web client sent the raw string to the server. However, with dynamic filters, this is no longer the case, and we need to parse domains to be able to combine them. In this commit, we modify the tokenizer to be able to work with escaped strings. closes odoo/odoo#29324 --- addons/web/static/lib/py.js/lib/py.js | 12 +++++++++--- addons/web/static/tests/core/py_utils_tests.js | 7 +++++++ 2 files changed, 16 insertions(+), 3 deletions(-) diff --git a/addons/web/static/lib/py.js/lib/py.js b/addons/web/static/lib/py.js/lib/py.js index 06d834321de..bd794323995 100644 --- a/addons/web/static/lib/py.js/lib/py.js +++ b/addons/web/static/lib/py.js/lib/py.js @@ -282,7 +282,10 @@ var py = {}; var name_pattern = new RegExp('^' + Name + '$'); var strip = new RegExp('^' + Whitespace); return function tokenize(s) { - var max=s.length, tokens = [], start, end = undefined; + s = s + .replace(/\\\"/g, '\\u0022') // for double quote + .replace(/\\\'/g, '\\u0027'); // for single quote + var max=s.length, tokens = [], start, end; // /g flag makes repeated exec() have memory var pseudoprog = new RegExp(PseudoToken, 'g'); @@ -302,7 +305,6 @@ var py = {}; end = pseudoprog.lastIndex; // strip leading space caught by Whitespace var token = s.slice(start, end).replace(strip, ''); - var initial = token[0]; if (number_pattern.test(token)) { tokens.push(create(symbols['(number)'], { @@ -310,9 +312,13 @@ var py = {}; })); } else if (string_pattern.test(token)) { var m = string_pattern.exec(token); + var value = (m[3] !== undefined ? m[3] : m[5]); + value + .replace(/\\u0022/g, '"') + .replace(/\\u0027/g, "'"); tokens.push(create(symbols['(string)'], { unicode: !!(m[2] || m[4]), - value: (m[3] !== undefined ? m[3] : m[5]) + value: value })); } else if (token in symbols) { var symbol; diff --git a/addons/web/static/tests/core/py_utils_tests.js b/addons/web/static/tests/core/py_utils_tests.js index d59fd30f957..be5760fc6c7 100644 --- a/addons/web/static/tests/core/py_utils_tests.js +++ b/addons/web/static/tests/core/py_utils_tests.js @@ -1254,6 +1254,13 @@ QUnit.module('core', function () { assert.checkAST(expr); }); + QUnit.test("parse escaped quoted strings", function (assert) { + assert.expect(2); + + assert.checkAST(`'\"'`, "a string containing \""); + assert.checkAST(`'\'`, "a string containing \'"); + }); + QUnit.module('pyutils (_normalizeDomain)'); QUnit.assert.checkNormalization = function (domain, normalizedDomain) {