From 6dde919bb9850912f618b561cd2141bffe41340c Mon Sep 17 00:00:00 2001 From: Nicolas Lempereur Date: Wed, 20 Jan 2016 10:28:23 +0100 Subject: [PATCH] [FIX] mail: don't autoescape mail subject The mail template rendering system use "autoescape" for subject, body, email_to, ... Using autoescape is good for the body, but for the subject it means variables insertions have to be marked as safe. This commit add another environment without autoescaping enabled for the subject field. From https://tools.ietf.org/html/rfc2822: The "Subject:" and "Comments:" fields are unstructured fields as defined in section 2.2.1, and therefore may contain text or folding white space. 2.2.1. Unstructured Header Field Bodies Some field bodies in this standard are defined simply as "unstructured" (which is specified below as any US-ASCII characters, except for CR and LF) with no further restrictions. closes #10547 opw-659231 opw-666801 opw-665863 --- addons/mail/models/mail_template.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/addons/mail/models/mail_template.py b/addons/mail/models/mail_template.py index a896de17d02..7577c00db13 100644 --- a/addons/mail/models/mail_template.py +++ b/addons/mail/models/mail_template.py @@ -1,6 +1,7 @@ # -*- coding: utf-8 -*- import base64 +import copy import datetime import dateutil.relativedelta as relativedelta import logging @@ -94,6 +95,8 @@ try: # is needed, apparently. 'relativedelta': lambda *a, **kw : relativedelta.relativedelta(*a, **kw), }) + mako_safe_template_env = copy.copy(mako_template_env) + mako_safe_template_env.autoescape = False except ImportError: _logger.warning("jinja2 not available, templating features will not work!") @@ -339,7 +342,8 @@ class MailTemplate(models.Model): # try to load the template try: - template = mako_template_env.from_string(tools.ustr(template_txt)) + mako_env = mako_safe_template_env if self.env.context.get('safe') else mako_template_env + template = mako_env.from_string(tools.ustr(template_txt)) except Exception: _logger.info("Failed to load template %r", template_txt, exc_info=True) return multi_mode and results or results[res_ids[0]] @@ -460,6 +464,7 @@ class MailTemplate(models.Model): if template.lang: Template = Template.with_context(lang=template._context.get('lang')) for field in fields: + Template = Template.with_context(safe=field in {'subject'}) generated_field_values = Template.render_template( getattr(template, field), template.model, template_res_ids, post_process=(field == 'body_html'))