ba8bba2add2794a13518d733429c327b1abc7eee
pos_*: pos_adyen, pos_six The use of the Markup was meant to keep the formatting (mostly the line breaks) of the data given by the payment terminals. The data was stored on the `ticket` attribute of the `Payment` model. A security issue arose from the fact that it is possible to import orders from a file via the debug widget. The `ticket` attribute was initialized in the `init_from_json` method and could be injected with some malicious code. Solution: Instead of replacing all line breaks by the `<br/>` tag whenever terminal data is retrieved, we can simply store this as it is in the `ticket` attribute. We then escape the value before replacing the line breaks when exporting the data as a Markup. With this, only our `<br/>` tags are trusted. closes odoo/odoo#114770 X-original-commit: 7194506648c3512dc6a80d4a92a986643e60c5d2 Related: odoo/enterprise#37962 Signed-off-by: Heinz Robin (rhe) <rhe@odoo.com> Signed-off-by: Trinh Jacky (trj) <trj@odoo.com>
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%