0ef25d19bc8cb0523ca21ee054ba86d25e7348cd
Issue
To do on Community:
- Install website_sale (eCommerce)
- Go into Website app
- Navigate through Product/Products
- Edit 'Customizable Desk (CONFIG)' and add '&' and/or '<' and/or '>'
characters into the name
- Save
- Go to the Website app Dashboard and click on 'Go to Website'
- Click on 'Edit' button
- Drag and drop the 'Dynamic Product' snippet into the website
- Click on the block 'Your Dynamic Snippet wil be ...'
- In the right panel, in the 'Dynamic Product' snippet options,
chose a 'Template' and a 'Product Category'
A traceback is shown
Cause
the '&' character crashes lxml.etree.fromstring
Solution
ensure no '&' is sent to lxmx.etree.fromstring by using
odoo.tools.html_escape (in order to ensure no other problematic
characters are sent to the front) on the field values except when
not applicable (widget rendering with record_to_html should not be
escaped).
It is important to note here that this is applicable
to action servers that are used by the dynamic filter.
opw-2357027
closes odoo/odoo#59805
X-original-commit: f91422115c09be484f2868347566b6392ed0effd
Signed-off-by: Jérémy Kersten (jke) <jke@openerp.com>
…
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%