[FIX] website_forum: fix the invalid URL link
How to reproduce: - Login as a portal user, create a new post by adding a URL link - Post Your Question - Login as admin to validate the post - Click on 'To Validate' from the moderation tool - Click on the mentioned URL Throws a Traceback and redirects to the about:blank#blocked page. Technical Reason: The '_update_content' method performs a regular expression on the link by using the escape method, which is later convert the backslash '\' into '%5C' while html_sanitize. After this commit: Clicking on the mentioned link redirects to the correct URL Task-3472776 closes odoo/odoo#148064 X-original-commit: dedfb9a42e7bade98756e73a3d6c54c581e99547 Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit is contained in:
@@ -426,8 +426,10 @@ class Post(models.Model):
|
||||
forum = self.env['forum.forum'].browse(forum_id)
|
||||
if content and self.env.user.karma < forum.karma_dofollow:
|
||||
for match in re.findall(r'<a\s.*href=".*?">', content):
|
||||
match = re.escape(match) # replace parenthesis or special char in regex
|
||||
content = re.sub(match, match[:3] + 'rel="nofollow" ' + match[3:], content)
|
||||
escaped_match = re.escape(match) # replace parenthesis or special char in regex
|
||||
url_match = re.match(r'^.*href="(.*)".*', match) # extracting the link allows to rebuild a clean link tag
|
||||
url = url_match.group(1)
|
||||
content = re.sub(escaped_match, f'<a rel="nofollow" href="{url}">', content)
|
||||
|
||||
if self.env.user.karma < forum.karma_editor:
|
||||
filter_regexp = r'(<img.*?>)|(<a[^>]*?href[^>]*?>)|(<[a-z|A-Z]+[^>]*style\s*=\s*[\'"][^\'"]*\s*background[^:]*:[^url;]*url)'
|
||||
|
||||
@@ -145,3 +145,14 @@ class TestTags(TestForumCommon):
|
||||
|
||||
self.assertEqual(self.base_forum.tag_most_used_ids, self.base_forum.tag_ids[:MOST_USED_TAGS_COUNT])
|
||||
self.assertEqual(self.base_forum.tag_unused_ids, self.env['forum.tag'])
|
||||
|
||||
def test_forum_post_link(self):
|
||||
content = 'This is a test link: <a href="https://www.example.com/route?param1=a¶m2=b" rel="ugc">test</a> Let make sure it works.'
|
||||
self.user_portal.karma = 50
|
||||
with self.with_user(self.user_portal.login):
|
||||
post = self.env['forum.post'].create({
|
||||
'name': "Post Forum test",
|
||||
'content': content,
|
||||
'forum_id': self.forum.id,
|
||||
})
|
||||
self.assertEqual(post.content, '<p>This is a test link: <a rel="nofollow" href="https://www.example.com/route?param1=a&param2=b">test</a> Let make sure it works.</p>')
|
||||
|
||||
Reference in New Issue
Block a user