* blacklist all fields by default
* don't use blacklist in get_authorized_fields which is called to see if
a field can be added to a form, instead only use it afterwards to see
if the field can be written to by the formbuilder. That way
formbuilder can whitelist fields which are actually added to forms
on-demand resulting in a more secure interaction
In some instance, the mail content of a sent form would only be text
formatted. This could lead to a message with no newline, thus making it
illegible.
This fix has to be ugly since body_html field of a mail.mail is of type
text.
In the form builder, custom field name could contain special char but
the get key values are of the type str whilst the value are in unicode
type.
Thus when concatenating them, one should be converted so they are
uniform and don't lead to an encoding error.
opw-656745
- Fixed the module name and category in manifest
- Fixed website_form_blacklisted being ignored
- Unauthorized readonly and magic fields
- Reset the form on successfull submit
- Added missing date field
- Added date and datetime validation
Now that most refactoring has been merged
It is better to have red a great work of another culture in translation than never to have read it at all.
― Henry Gratton Doyle
They are supposed to be removed by clean_for_save, but when
someone breaks it, the result is a js error here instead of
a proper error in the subsequent tour steps.