From ba8bba2add2794a13518d733429c327b1abc7eee Mon Sep 17 00:00:00 2001 From: "Jacky (trj)" Date: Fri, 24 Feb 2023 14:32:25 +0000 Subject: [PATCH] [FIX] point_of_sale, pos_*: improve Markup pos_*: pos_adyen, pos_six The use of the Markup was meant to keep the formatting (mostly the line breaks) of the data given by the payment terminals. The data was stored on the `ticket` attribute of the `Payment` model. A security issue arose from the fact that it is possible to import orders from a file via the debug widget. The `ticket` attribute was initialized in the `init_from_json` method and could be injected with some malicious code. Solution: Instead of replacing all line breaks by the `
` tag whenever terminal data is retrieved, we can simply store this as it is in the `ticket` attribute. We then escape the value before replacing the line breaks when exporting the data as a Markup. With this, only our `
` tags are trusted. closes odoo/odoo#114770 X-original-commit: 7194506648c3512dc6a80d4a92a986643e60c5d2 Related: odoo/enterprise#37962 Signed-off-by: Heinz Robin (rhe) Signed-off-by: Trinh Jacky (trj) --- addons/point_of_sale/static/src/js/models.js | 6 ++++-- addons/pos_adyen/static/src/js/payment_adyen.js | 5 ++--- addons/pos_six/static/src/js/payment_six.js | 6 +++--- 3 files changed, 9 insertions(+), 8 deletions(-) diff --git a/addons/point_of_sale/static/src/js/models.js b/addons/point_of_sale/static/src/js/models.js index fd18c59c28a..eefc0815e70 100644 --- a/addons/point_of_sale/static/src/js/models.js +++ b/addons/point_of_sale/static/src/js/models.js @@ -12,6 +12,7 @@ import { ErrorPopup } from "./Popups/ErrorPopup"; import { ProductConfiguratorPopup } from "@point_of_sale/js/Popups/ProductConfiguratorPopup"; import { EditListPopup } from "@point_of_sale/js/Popups/EditListPopup"; import { markRaw, reactive } from "@odoo/owl"; +import { escape } from "@web/core/utils/strings"; var QWeb = core.qweb; var _t = core._t; @@ -2578,12 +2579,13 @@ export class Payment extends PosModel { }; } //exports as JSON for receipt printing - export_for_printing() { + export_for_printing(){ + const ticket = escape(this.ticket).replace(/\n/g, "
"); // formatting return { cid: this.cid, amount: this.get_amount(), name: this.name, - ticket: Markup(this.ticket), + ticket: Markup(ticket), }; } // If payment status is a non-empty string, then it is an electronic payment. diff --git a/addons/pos_adyen/static/src/js/payment_adyen.js b/addons/pos_adyen/static/src/js/payment_adyen.js index bcd9b1b8f39..e423c5d3681 100644 --- a/addons/pos_adyen/static/src/js/payment_adyen.js +++ b/addons/pos_adyen/static/src/js/payment_adyen.js @@ -191,11 +191,10 @@ export const PaymentAdyen = PaymentInterface.extend({ _convert_receipt_info: function (output_text) { return output_text.reduce(function (acc, entry) { var params = new URLSearchParams(entry.Text); - if (params.get("name") && !params.get("value")) { - return acc + _.str.sprintf("
%s", params.get("name")); + return acc + _.str.sprintf("\n%s", params.get("name")); } else if (params.get("name") && params.get("value")) { - return acc + _.str.sprintf("
%s: %s", params.get("name"), params.get("value")); + return acc + _.str.sprintf("\n%s: %s", params.get("name"), params.get("value")); } return acc; diff --git a/addons/pos_six/static/src/js/payment_six.js b/addons/pos_six/static/src/js/payment_six.js index 855fdef930b..5f3b712a5fa 100644 --- a/addons/pos_six/static/src/js/payment_six.js +++ b/addons/pos_six/static/src/js/payment_six.js @@ -4,6 +4,7 @@ import core from "web.core"; import { PaymentInterface } from "@point_of_sale/js/payment"; import { ErrorPopup } from "@point_of_sale/js/Popups/ErrorPopup"; +import { escape } from "@web/core/utils/strings"; var _t = core._t; @@ -152,18 +153,17 @@ export const PaymentSix = PaymentInterface.extend({ _printReceipts: function (receipts) { _.forEach(receipts, (receipt) => { - var value = receipt.value.replace(/\n/g, "
"); if ( receipt.recipient === timapi.constants.Recipient.merchant && this.pos.env.proxy.printer ) { this.pos.env.proxy.printer.print_receipt( "
" + - value + + escape(receipt.value).replace(/\n/g, "
") + "
" ); } else if (receipt.recipient === timapi.constants.Recipient.cardholder) { - this.pos.get_order().selected_paymentline.set_receipt_info(value); + this.pos.get_order().selected_paymentline.set_receipt_info(receipt.value); } }); },