Files
odoo_source/odoo/addons/base/controllers
nda f67db6fe1e [FIX] core: remove control characters from strings for xmlrpc
According to https://docs.python.org/3.7/library/xmlrpc.client.html :

When passing strings, characters special to XML such as <, >, and & will be
automatically escaped. However, it’s the caller’s responsibility to ensure that
the string is free of characters that aren’t allowed in XML, such as the
control characters with ASCII values between 0 and 31 (except, of course, tab,
newline and carriage return); failing to do this will result in an XML-RPC
request that isn’t well-formed XML.

This commit implements the removal of control characters from strings. As we
convert binary data to a string and return it, the resulting string should not
contain forbidden characters neither. The modification of dump_unicode function
now fulfills this requirement and can be applied to dump_bytes, contributing
to a more consistent behavior overall.

steps to reproduce:
- create a product with an ASCII control character in its name (ex: \x03)
- read the product name using XMLRPC

before this commit:
- client can't parse the response, an error is raised

after this commit:
- we make sure the string is free of those characters

opw-3617458

closes odoo/odoo#153084

X-original-commit: 3fa92ff58daef0dd2464beadeafef208871deca6
Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
Signed-off-by: Nicolas Danhier (nda) <nda@odoo.com>
2024-02-07 18:34:24 +00:00
..