%s' % misc.html_escape(ext.decode('utf-8')), html)
def test_quote_thunderbird(self):
html = html_sanitize(test_mail_examples.QUOTE_THUNDERBIRD_1)
for ext in test_mail_examples.QUOTE_THUNDERBIRD_1_IN:
self.assertIn(ext, html)
for ext in test_mail_examples.QUOTE_THUNDERBIRD_1_OUT:
- self.assertIn('%s' % cgi.escape(ext.decode('utf-8')), html)
+ self.assertIn('%s' % misc.html_escape(ext.decode('utf-8')), html)
def test_quote_hotmail_html(self):
html = html_sanitize(test_mail_examples.QUOTE_HOTMAIL_HTML)
@@ -226,7 +225,7 @@ class TestSanitizer(unittest.TestCase):
for text in in_lst:
self.assertIn(text, new_html)
for text in out_lst:
- self.assertIn('%s' % cgi.escape(text), new_html)
+ self.assertIn('%s' % misc.html_escape(text), new_html)
def test_quote_signature(self):
test_data = [
@@ -245,27 +244,27 @@ class TestSanitizer(unittest.TestCase):
for ext in test_mail_examples.GMAIL_1_IN:
self.assertIn(ext, html)
for ext in test_mail_examples.GMAIL_1_OUT:
- self.assertIn('%s' % cgi.escape(ext), html)
+ self.assertIn('%s' % misc.html_escape(ext), html)
def test_quote_text(self):
html = html_sanitize(test_mail_examples.TEXT_1)
for ext in test_mail_examples.TEXT_1_IN:
self.assertIn(ext, html)
for ext in test_mail_examples.TEXT_1_OUT:
- self.assertIn('%s' % cgi.escape(ext), html)
+ self.assertIn('%s' % misc.html_escape(ext), html)
html = html_sanitize(test_mail_examples.TEXT_2)
for ext in test_mail_examples.TEXT_2_IN:
self.assertIn(ext, html)
for ext in test_mail_examples.TEXT_2_OUT:
- self.assertIn('%s' % cgi.escape(ext), html)
+ self.assertIn('%s' % misc.html_escape(ext), html)
def test_quote_bugs(self):
html = html_sanitize(test_mail_examples.BUG1)
for ext in test_mail_examples.BUG_1_IN:
self.assertIn(ext, html)
for ext in test_mail_examples.BUG_1_OUT:
- self.assertIn('%s' % cgi.escape(ext.decode('utf-8')), html)
+ self.assertIn('%s' % misc.html_escape(ext.decode('utf-8')), html)
def test_misc(self):
# False / void should not crash
diff --git a/odoo/addons/base/tests/test_qweb.py b/odoo/addons/base/tests/test_qweb.py
index cd459fe7669..c331f426748 100644
--- a/odoo/addons/base/tests/test_qweb.py
+++ b/odoo/addons/base/tests/test_qweb.py
@@ -1,19 +1,17 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
-import cgi
import collections
import json
import os.path
import re
from lxml import etree
-from itertools import chain
from odoo.modules import get_module_resource
from odoo.tests.common import TransactionCase
from odoo.addons.base.ir.ir_qweb import QWebException
-from odoo.tools import pycompat
+from odoo.tools import pycompat, misc, ustr
def dedent_and_strip(string):
@@ -48,12 +46,12 @@ class TestQWebTField(TransactionCase):
result = self.engine.render(field, {'company': company})
self.assertEqual(
- result,
+ ustr(result),
'%s' % (
company.id,
- cgi.escape(s.encode('utf-8')),
+ misc.html_escape(s),
),
)
diff --git a/odoo/tools/mail.py b/odoo/tools/mail.py
index 9689512df00..f3396f9137b 100644
--- a/odoo/tools/mail.py
+++ b/odoo/tools/mail.py
@@ -1,7 +1,6 @@
# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
-import cgi
import logging
import lxml.html.clean as clean
import random
@@ -16,7 +15,7 @@ from lxml import etree
import odoo
from odoo.loglevels import ustr
-from odoo.tools import pycompat
+from odoo.tools import pycompat, misc
_logger = logging.getLogger(__name__)
@@ -178,10 +177,10 @@ def html_sanitize(src, silent=True, sanitize_tags=True, sanitize_attributes=Fals
part = re.compile(r"(<(([^a<>]|a[^<>\s])[^<>]*)@[^<>]+>)", re.IGNORECASE | re.DOTALL)
# remove results containing cite="mid:email_like@address" (ex: blockquote cite)
# cite_except = re.compile(r"^((?!cite[\s]*=['\"]).)*$", re.IGNORECASE)
- src = part.sub(lambda m: ('cite=' not in m.group(1) and 'alt=' not in m.group(1)) and cgi.escape(m.group(1)) or m.group(1), src)
+ src = part.sub(lambda m: ('cite=' not in m.group(1) and 'alt=' not in m.group(1)) and misc.html_escape(m.group(1)) or m.group(1), src)
# html encode mako tags <% ... %> to decode them later and keep them alive, otherwise they are stripped by the cleaner
- src = src.replace('<%', cgi.escape('<%'))
- src = src.replace('%>', cgi.escape('%>'))
+ src = src.replace('<%', misc.html_escape('<%'))
+ src = src.replace('%>', misc.html_escape('%>'))
kwargs = {
'page_structure': True,
@@ -334,7 +333,7 @@ def html2plaintext(html, body_id=None, encoding='utf-8'):
def plaintext2html(text, container_tag=False):
""" Convert plaintext into html. Content of the text is escaped to manage
- html entities, using cgi.escape().
+ html entities, using misc.html_escape().
- all \n,\r are replaced by
- enclose content into
- convert url into clickable link
@@ -343,7 +342,7 @@ def plaintext2html(text, container_tag=False):
:param string container_tag: container of the html; by default the
content is embedded into a
"""
- text = cgi.escape(ustr(text))
+ text = misc.html_escape(ustr(text))
# 1. replace \n and \r
text = text.replace('\n', '
')