Files
odoo_source/addons/mail_bot/models/res_users.py
T
Martin Trigaux 69f911d994 [IMP] *: enforce usage of Markup in mail
When using message_post, the body format must be explicitly specified.
If html is expected, a Markup object should be used.
If text is given, the content will be escaped.

Before this PR:
message_post was unaware if the content of a message was HTML or
text. This lead to multiple situation where the content was
incorrectly considered as HTML and led to display errors.
In
  self.message_post(body="Hello %s!" % self.name)
if the name contained HTML, it would be evaluated.

In
  self.message_post(body="Contact Raoul <raoul@caramail.be>")
the email would not be displayed as considered as unknown HTML and
discarded by the sanitizer

Now each call must explict the type of content.
Use the escape() helper to properly combine Markup and translations.
It would also be acceptable to use Markup() to wrap a static
translation but escape is better as one can not guarantee the content
of a translation.

closes odoo/odoo#111850

Related: odoo/documentation#3612
Related: odoo/enterprise#36728
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
2023-04-13 16:39:48 +02:00

45 lines
1.9 KiB
Python

# -*- coding: utf-8 -*-
# Part of Odoo. See LICENSE file for full copyright and licensing details.
from markupsafe import Markup
from odoo import models, fields, _
class Users(models.Model):
_inherit = 'res.users'
odoobot_state = fields.Selection(
[
('not_initialized', 'Not initialized'),
('onboarding_emoji', 'Onboarding emoji'),
('onboarding_attachement', 'Onboarding attachment'),
('onboarding_command', 'Onboarding command'),
('onboarding_ping', 'Onboarding ping'),
('idle', 'Idle'),
('disabled', 'Disabled'),
], string="OdooBot Status", readonly=True, required=False) # keep track of the state: correspond to the code of the last message sent
odoobot_failed = fields.Boolean(readonly=True)
@property
def SELF_READABLE_FIELDS(self):
return super().SELF_READABLE_FIELDS + ['odoobot_state']
def _init_messaging(self):
if self.odoobot_state in [False, 'not_initialized'] and self._is_internal():
self._init_odoobot()
return super()._init_messaging()
def _init_odoobot(self):
self.ensure_one()
odoobot_id = self.env['ir.model.data']._xmlid_to_res_id("base.partner_root")
channel_info = self.env['mail.channel'].channel_get([odoobot_id, self.partner_id.id])
channel = self.env['mail.channel'].browse(channel_info['id'])
message = Markup("%s<br/>%s<br/><b>%s</b> <span class=\"o_odoobot_command\">:)</span>") % (
_("Hello,"),
_("Odoo's chat helps employees collaborate efficiently. I'm here to help you discover its features."),
_("Try to send me an emoji")
)
channel.sudo().message_post(body=message, author_id=odoobot_id, message_type="comment", subtype_xmlid="mail.mt_comment")
self.sudo().odoobot_state = 'onboarding_emoji'
return channel