[FIX] web_editor: escape for xml in translation as done in ir.ui.view

Currently server side there is two differents source for html content
displayed on a qweb rendered page:

1) ir.ui.view arch value

are stored as xml and are unescaped before being displayed, so we have
to escape the text nodes before saving.

e.g:

*   should be stored as   since it is an HTML entity but
  not a defined XML entity,
* & should be stored as & since when unescaping it, it
  would become & which is invalid in HTML,
* < should be stored as < since when unescaping it, it would
  become `<` so HTML text node could become HTML element node.

The tag themselves can also be escaped but it often has the same result:
&lt;em&;gt;blah&lt;/em&gt; is the same as <em>blah</em> when unescaping
is applied to both.

But it is required is some instance, e.g <!DOCTYPE html> unescaped would
be invalid xml.

2) openerp.fields.Html value

are stored directly in HTML formatting and should, conversely, not be
escaped before being stored.

Thus when saving an ir.ui.view part modified thanks to the website
editor, an escaping of text node content is carried out to take this
into account, but the same was currently not done for the v9.0 new
translation system.

This commit apply the same logic when saving ir.ui.view as when saving
ir.translation values.
This commit is contained in:
Nicolas Lempereur
2015-11-03 13:35:19 +01:00
parent 87a889669d
commit f5acea7f9c
2 changed files with 17 additions and 10 deletions
+15 -9
View File
@@ -420,14 +420,10 @@ var RTE = Widget.extend({
});
},
saveElement: function ($el, context) {
// remove multi edition
if ($el.data('oe-model')) {
var key = $el.data('oe-model')+":"+$el.data('oe-id')+":"+$el.data('oe-field')+":"+$el.data('oe-type')+":"+$el.data('oe-expression');
if (this.__saved[key]) return true;
this.__saved[key] = true;
}
// escape text nodes for xml saving
/**
* Get HTML cloned element with text nodes escaped for XML storage
*/
getEscapedElement: function($el) {
var escaped_el = $el.clone();
var to_escape = escaped_el.find('*').addBack();
to_escape = to_escape.not(to_escape.filter('object,iframe,script,style,[data-oe-model][data-oe-model!="ir.ui.view"]').find('*').addBack());
@@ -436,7 +432,17 @@ var RTE = Widget.extend({
this.nodeValue = $('<div />').text(this.nodeValue).html();
}
});
var markup = escaped_el.prop('outerHTML');
return escaped_el;
},
saveElement: function ($el, context) {
// remove multi edition
if ($el.data('oe-model')) {
var key = $el.data('oe-model')+":"+$el.data('oe-id')+":"+$el.data('oe-field')+":"+$el.data('oe-type')+":"+$el.data('oe-expression');
if (this.__saved[key]) return true;
this.__saved[key] = true;
}
var markup = this.getEscapedElement($el).prop('outerHTML');
return ajax.jsonRpc('/web/dataset/call', 'call', {
model: 'ir.ui.view',
@@ -41,13 +41,14 @@ var RTE_Translate = rte.Class.extend({
var key = 'translation:'+$el.data('oe-translation-id');
if (this.__saved[key]) return true;
this.__saved[key] = true;
var translation_content = this.getEscapedElement($el).html();
return ajax.jsonRpc('/web/dataset/call', 'call', {
model: 'ir.translation',
method: 'write',
args: [
[+$el.data('oe-translation-id')],
{value: $el.html(), state: 'translated'},
{value: translation_content, state: 'translated'},
context || base.get_context()
],
});