Jacky (trj) ba8bba2add [FIX] point_of_sale, pos_*: improve Markup
pos_*: pos_adyen, pos_six

The use of the Markup was meant to keep the formatting (mostly the line breaks) of the data
given by the payment terminals. The data was stored on the `ticket` attribute of the `Payment`
model. A security issue arose from the fact that it is possible to import orders from a file
via the debug widget.
The `ticket` attribute was initialized in the `init_from_json` method and could be injected
with some malicious code.

Solution:
Instead of replacing all line breaks by the `<br/>` tag whenever terminal data is retrieved,
we can simply store this as it is in the `ticket` attribute. We then escape the value before
replacing the line breaks when exporting the data as a Markup. With this, only our `<br/>` tags
are trusted.

closes odoo/odoo#114770

X-original-commit: 7194506648c3512dc6a80d4a92a986643e60c5d2
Related: odoo/enterprise#37962
Signed-off-by: Heinz Robin (rhe) <rhe@odoo.com>
Signed-off-by: Trinh Jacky (trj) <trj@odoo.com>
2023-03-09 15:54:58 +01:00
…
…
…
…
2023-01-03 13:16:02 +01:00
2023-01-03 13:16:02 +01:00

Build Status Tech Doc Help Nightly Builds

Odoo

Odoo is a suite of web based open source business apps.

The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...

Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.

Getting started with Odoo

For a standard installation please follow the Setup instructions from the documentation.

To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials

S
Description
No description provided
Readme LGPL-3.0
3.4 GiB
Languages
Python 49.6%
JavaScript 47.8%
SCSS 2%
CSS 0.3%
HTML 0.2%