Files
odoo_source/addons/web_editor/static
abd-msyukyu-odoo 20807fe800 [FIX] web_editor: don't sanitize recursively during safeSetAttribute
In Knowledge, embedded views anchors have a `data-behavior-props` attribute
containing information on how to render the embedded view. That attribute is
sometimes updated, and during a collaborative session, receiving such an update
as a collaborative step would trigger a full sanitization of the embedded view,
possibly discarding some transient content that could break the view, even
though it caused no security issue since it is all rendered on a per client
basis (each client fully renders its own view).

The proposed solution is to sanitize only the attribute of the node and not its
content during `_safeSetAttribute`, which is reasonable, because the node
content is already sanitized recursively for `add` mutations.

task-3060490

closes odoo/odoo#157669

X-original-commit: d9e3d7bdb6e13e6049a86ed08160daccf0fcbcc8
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2024-03-14 15:43:46 +00:00
..