Files
odoo_source/addons/website/models/ir_qweb_fields.py
T
Romain DerieandVranckx Florian 7c6844fa6c [FIX] website: make forms work again when inside html fields
Recent commit [1] in Odoo 15 (which is a backport of commit [2] which
was merged in Odoo 17) introduced a security layer on forms but only
for forms which are inside `ir.ui.view`. The forms inside HTML fields
are thus not working anymore, because those don't receive the required
signature.

For the record:
- `ir.ui.view` = `website.page` pages, some part of the controller pages
- HTML fields = the most part of the editable areas in controller pages

[1]: https://github.com/odoo/odoo/commit/17c6f6f30bf13bd3c303b28d9a314bd76dd8f4dc
[2]: https://github.com/odoo/odoo/commit/7d25e7bf9243367c87b1b2005587ae728730b49c

opw-3586333

closes odoo/odoo#143139

closes odoo/odoo#143879

X-original-commit: 5e5a14ae4a522a589f6112d1687bb910f86f9a6d
Signed-off-by: Jérémy Kersten <jke@odoo.com>
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Co-authored-by: Vranckx Florian (flvr) <flvr@odoo.com>
Co-authored-by: Romain Derie <rde@odoo.com>
2023-11-30 07:37:14 +00:00

40 lines
1.3 KiB
Python

# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from lxml import etree
from markupsafe import Markup
from odoo import api, models, _
from odoo.addons.website.tools import add_form_signature
class Contact(models.AbstractModel):
_inherit = 'ir.qweb.field.contact'
@api.model
def get_available_options(self):
options = super(Contact, self).get_available_options()
options.update(
website_description=dict(type='boolean', string=_('Display the website description')),
UserBio=dict(type='boolean', string=_('Display the biography')),
badges=dict(type='boolean', string=_('Display the badges'))
)
return options
class HTML(models.AbstractModel):
_inherit = 'ir.qweb.field.html'
@api.model
def value_to_html(self, value, options):
res = super().value_to_html(value, options)
if res and '<form' in res: # Efficient check
# The usage of `fromstring`, `HTMLParser`, `tostring` and `Markup`
# is replicating what is done in the `super()` implementation.
body = etree.fromstring("<body>%s</body>" % res, etree.HTMLParser())[0]
add_form_signature(body, self.sudo().env)
res = Markup(etree.tostring(body, encoding='unicode', method='html')[6:-7])
return res