Files
odoo_source/addons/stock/controllers/main.py
T
Julien (jula) 926d8c6c5d [FIX] web, stock: escape JSON error when downloading report
__Description of the issue:__

When something goes wrong while downloading a report file, a 500 error
is sent as JSON. However the frontend interprets this response as HTML
and then try to parse the text content as JSON.

Most of the time this works, but if the response contains any HTML tags,
like `<lambda>` from a Python stacktrace, the JSON response will get
misinterpreted as HTML instead of regular text, causing the subsequent
JSON interpretation to fail.

The end result for the user is that empty tracebacks will be displayed
instead of User Errors or actual tracebacks.

__Desired behavior:__

The JSON response is HTML escaped before being sent and will therefore
be correctly parsed and displayed to the user.

This basically restore what was done prior of #104594.

Enterprise: odoo/enterprise#36523
X-original-commit: 5999a7d336553053c5638f69344cdfbc84a8c681
Part-of: odoo/odoo#112453
2023-02-12 14:14:41 +01:00

39 lines
1.5 KiB
Python

# -*- coding: utf-8 -*-
import werkzeug
from werkzeug.exceptions import InternalServerError
from odoo import http
from odoo.http import request
from odoo.tools.misc import html_escape
import json
class StockReportController(http.Controller):
@http.route('/stock/<string:output_format>/<string:report_name>', type='http', auth='user')
def report(self, output_format, report_name=False, **kw):
uid = request.session.uid
domain = [('create_uid', '=', uid)]
stock_traceability = request.env['stock.traceability.report'].with_user(uid).search(domain, limit=1)
line_data = json.loads(kw['data'])
try:
if output_format == 'pdf':
response = request.make_response(
stock_traceability.with_context(active_id=kw['active_id'], active_model=kw['active_model']).get_pdf(line_data),
headers=[
('Content-Type', 'application/pdf'),
('Content-Disposition', 'attachment; filename=' + 'stock_traceability' + '.pdf;')
]
)
return response
except Exception as e:
se = http.serialize_exception(e)
error = {
'code': 200,
'message': 'Odoo Server Error',
'data': se
}
res = request.make_response(html_escape(json.dumps(error)))
raise InternalServerError(response=res) from e