From fab86bbf8bc8620ee1eeb53ff861cac1f3978bd2 Mon Sep 17 00:00:00 2001 From: Christophe Monniez Date: Mon, 6 Feb 2023 15:41:03 +0000 Subject: [PATCH] [FIX] web: adapt test for werkzeug >= 2.2.2 In werkzeug 2.2.2, the following characters "$!'()*+,;" are now considered as safe by url_quote. This makes the filename_secure test fail with the hard coded expected string containing a single quote as '%27'. This commit adapt the filename_secure test in order to work with all versions of werkzeug. closes odoo/odoo#112298 Signed-off-by: Julien Castiaux (juc) Signed-off-by: Christophe Monniez (moc) --- addons/web/tests/test_image.py | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/addons/web/tests/test_image.py b/addons/web/tests/test_image.py index 7b55ec2cd7e..943ddeded4c 100644 --- a/addons/web/tests/test_image.py +++ b/addons/web/tests/test_image.py @@ -5,8 +5,8 @@ import io import base64 from PIL import Image +from werkzeug.urls import url_quote -from odoo.http import content_disposition from odoo.tests.common import HttpCase, tagged @@ -103,7 +103,8 @@ class TestImage(HttpCase): }) res = self.url_open(f'/web/image/{att.id}') - self.assertEqual(res.headers['Content-Disposition'], 'inline; filename="foo-l\'eb _ a\\"!r\\".gif"; filename*=UTF-8\'\'f%C3%B4%E2%98%BAo-l%27%C3%A9b%20_%20a%22%21r%22.gif') + expected_ufilename = url_quote(att.name.replace('\n', '_').replace('\r', '_')) + self.assertEqual(res.headers['Content-Disposition'], r"""inline; filename="foo-l'eb _ a\"!r\".gif"; filename*=UTF-8''""" + expected_ufilename) res.raise_for_status() res = self.url_open(f'/web/image/{att.id}/custom_invalid_name\nis-ok.gif')