From a64a72188b190074c55fea02aa170a7b08f74ff2 Mon Sep 17 00:00:00 2001 From: Renaud Thiry Date: Fri, 20 Jan 2023 09:21:09 +0000 Subject: [PATCH] [FIX] mail: remove MAKO compatibility Before this change URLs would get their url-safe encoding replaced with regular characters when cleaning up html content. This caused signed URLs that use some of those characters to become invalid if the target did not accept equivalent characters. Concrete example: /markers=size%3Alittle%7CAddress is not the same as /markers=size%3Alittle|Address for google maps signed static urls Do not add special handling for MAKO patterns as they are not used in templates anymore task - 3079113 Part-of: odoo/odoo#107200 --- odoo/tools/mail.py | 10 ---------- 1 file changed, 10 deletions(-) diff --git a/odoo/tools/mail.py b/odoo/tools/mail.py index 5271c302adc..0f6a8c86b30 100644 --- a/odoo/tools/mail.py +++ b/odoo/tools/mail.py @@ -223,16 +223,6 @@ def html_sanitize(src, silent=True, sanitize_tags=True, sanitize_attributes=Fals cleaner = _Cleaner(**kwargs) cleaned = cleaner.clean_html(src) assert isinstance(cleaned, str) - # MAKO compatibility: $, { and } inside quotes are escaped, preventing correct mako execution - cleaned = cleaned.replace(u'%24', u'$') - cleaned = cleaned.replace(u'%7B', u'{') - cleaned = cleaned.replace(u'%7D', u'}') - cleaned = cleaned.replace(u'%20', u' ') - cleaned = cleaned.replace(u'%5B', u'[') - cleaned = cleaned.replace(u'%5D', u']') - cleaned = cleaned.replace(u'%7C', u'|') - cleaned = cleaned.replace(u'<%', u'<%') - cleaned = cleaned.replace(u'%>', u'%>') # html considerations so real html content match database value cleaned = cleaned.replace(u'\xa0', u' ') except etree.ParserError as e: