c0da919697bcf06d76ebb539e951bc8c4f46fa9d
This commit allows to define html fields in discuss models,
so that when insert is trusted they are automatically markup.
By default, all model insert are untrusted. To make a trusted
insertion, we should pass 2nd parameter `{ html: true }` to
an `insert()` method. The param is intentionally named `html`
instead of `trusted`, so that it triggers ci/security for
reviewers awareness.
It's still possible to immediately assign a markup on the html
fields, like before.
This changes simplifies the code, so that we don't have to dissect
model data everytime and make sure all bits are properly markup.
The dissect operation added many LOCs and we frequently missed to
markup the data in some flows. Being able to flag html fields at
model definition and flagging an insert safe keeps the security
concern while helping properly markup-ing all the data.
Part-of: odoo/odoo#139501
…
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%