[IMP] web_editor: ignore data-behavior-props for sanitize

DOMPurify.sanitize removes an attribute that contains a ">" for security
reasons. Make an exception for `data-behavior-props`.

That exception allows Embedded views in Knowledge to store a JSON object
containing the act_window data used to render it as an attribute of the
HTMLElement where it is supposed to be rendered (The view contents are
not saved in the html_field value).

More generally, data-behavior-props should be used when storing properties for a
Behavior Component (see Knowledge module) is required.

Prepares Task-2796156
Prepares odoo/enterprise#29423

X-original-commit: aeb9df5247a3936b1397d8056c1725a1de660b6a
Part-of: odoo/odoo#101694
This commit is contained in:
abd-msyukyu-odoo
2022-09-30 10:33:02 +02:00
committed by Thibault Delavallée
parent 62a8aec2b5
commit e6497fb0e8
@@ -3922,7 +3922,20 @@ export class OdooEditor extends EventTarget {
const clipboardHtml = ev.clipboardData.getData('text/html');
if (odooEditorHtml) {
const fragment = parseHTML(odooEditorHtml);
// DOMPurify.sanitize remove an attribute that contains a ">" for
// security reasons. Make an exception for `data-behavior-props`.
// Encoding it hides the character ">".
for (const el of fragment.querySelectorAll('[data-behavior-props]')) {
el.setAttribute('data-behavior-props', encodeURIComponent(el.getAttribute('data-behavior-props')));
}
DOMPurify.sanitize(fragment, { IN_PLACE: true });
for (const el of fragment.querySelectorAll('[data-behavior-props]')) {
el.setAttribute('data-behavior-props', decodeURIComponent(el.getAttribute('data-behavior-props')));
}
if (fragment.hasChildNodes()) {
this.execCommand('insert', fragment);
}