[FIX] mail: remove MAKO compatibility
Before this change URLs would get their url-safe encoding replaced with regular characters when cleaning up html content. This caused signed URLs that use some of those characters to become invalid if the target did not accept equivalent characters. Concrete example: /markers=size%3Alittle%7CAddress is not the same as /markers=size%3Alittle|Address for google maps signed static urls Do not add special handling for MAKO patterns as they are not used in templates anymore task - 3079113 Part-of: odoo/odoo#107200
This commit is contained in:
@@ -223,16 +223,6 @@ def html_sanitize(src, silent=True, sanitize_tags=True, sanitize_attributes=Fals
|
||||
cleaner = _Cleaner(**kwargs)
|
||||
cleaned = cleaner.clean_html(src)
|
||||
assert isinstance(cleaned, str)
|
||||
# MAKO compatibility: $, { and } inside quotes are escaped, preventing correct mako execution
|
||||
cleaned = cleaned.replace(u'%24', u'$')
|
||||
cleaned = cleaned.replace(u'%7B', u'{')
|
||||
cleaned = cleaned.replace(u'%7D', u'}')
|
||||
cleaned = cleaned.replace(u'%20', u' ')
|
||||
cleaned = cleaned.replace(u'%5B', u'[')
|
||||
cleaned = cleaned.replace(u'%5D', u']')
|
||||
cleaned = cleaned.replace(u'%7C', u'|')
|
||||
cleaned = cleaned.replace(u'<%', u'<%')
|
||||
cleaned = cleaned.replace(u'%>', u'%>')
|
||||
# html considerations so real html content match database value
|
||||
cleaned = cleaned.replace(u'\xa0', u' ')
|
||||
except etree.ParserError as e:
|
||||
|
||||
Reference in New Issue
Block a user