Files
odoo_source/addons/website/controllers
bram1000andBenoit Socias 4e110638f0 [FIX] website: HTML-escape submitted form fields
When fields are submitted through the website form, their values are
used as they are. Because of this it is possible to include HTML in the
sent email while this is not desired.

To avoid this, this commit HTML-encodes the values received for custom
fields and html fields.

Steps to reproduce (with default_field):
- Go to the "Contact us" page with form untouched (it should send mail)
- Fill in the form
- In the name put John <b>Smith</b>
- Submit the form
- You will see that Smith will be in bold in the received mail

Steps to reproduce (no default_field):
- Install website_recruitment
- Go to the "Contact us" page
- Enter edit mode
- Change the form type to apply for a job (and select a job to apply in
  the right panel option, like "Consultant")
- In debug mode in the backend, go to ir.model fields
- Find "Applicant (hr.applicant) record and edit it
- Remove the website_form_default_field_id in the "Website Forms" tab of
  the form view of this record
- Back to the "contactus page", add a new custom field to the form
- Now, out of edit mode, add "<b>Something</b>" in the custom field and
  submit the form
- Find the job application in the backend in the recruitment module, it
  should be inside the "Consultant" job.
- You will see the "Something" in bold in the chatter

Note: In Odoo 16.2, commit [1] is already doing something similar for
      one of the 2 places fixed here.

[1]: https://github.com/odoo/odoo/commit/3e7acff8d9302c3332fe3011f75374170484c61d

task-3650953

closes odoo/odoo#152170

X-original-commit: c2e934f421a8afee4ce537b1e03871a1bcef99d1
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Signed-off-by: Bram Van Gaal (brvg) <brvg@odoo.com>
Co-authored-by: bram1000 <brvg@odoo.com>
Co-authored-by: Benoit Socias <bso@odoo.com>
2024-02-01 09:49:59 +00:00
..
…
…
…