Files
odoo_source/odoo
Christophe Monniez f194271823 [FIX] http: comply with rfc6265
Werkzeug changed the behavior of url_quote in
pallets/werkzeug@babfc93b38

Which appeared in Werkzeug 2.2.2 used in Debian Bookworm.

This change broke at least the export feature in Odoo. In summary,
the character set specified by [RFC5987] is more restricted than
that of [RFC3986]. So url_quote now allows invalid characters.

For example, a filename like `Journal Entry (account.move).xlsx`
leads to a crash of the client with Werkzeug 2.2.2.

url_quote is not really made to conform to [RFC6266] but we did not
find any [RFC6266] escaping tool in the standard library. This
commit explicitly specify as unsafe this list of chars.

[RFC6266]: https://datatracker.ietf.org/doc/html/rfc6266/ [RFC5987]:
https://datatracker.ietf.org/doc/html/rfc5987#section-3.2 [RFC3986]:
https://datatracker.ietf.org/doc/html/rfc3986/ [RFC2616]:
https://datatracker.ietf.org/doc/html/rfc2616#section-2

closes odoo/odoo#139483

X-original-commit: d145cb57eaf39fbe7612d4a79f209fc191828a8b
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
Signed-off-by: Christophe Monniez (moc) <moc@odoo.com>
2023-10-24 13:55:28 +00:00
..
2023-10-24 13:55:28 +00:00
…
2022-10-19 15:12:44 +02:00
2023-10-24 13:55:28 +00:00
2023-09-27 03:01:44 +00:00