When using message_post, the body format must be explicitly specified. If html is expected, a Markup object should be used. If text is given, the content will be escaped. Before this PR: message_post was unaware if the content of a message was HTML or text. This lead to multiple situation where the content was incorrectly considered as HTML and led to display errors. In self.message_post(body="Hello %s!" % self.name) if the name contained HTML, it would be evaluated. In self.message_post(body="Contact Raoul <raoul@caramail.be>") the email would not be displayed as considered as unknown HTML and discarded by the sanitizer Now each call must explict the type of content. Use the escape() helper to properly combine Markup and translations. It would also be acceptable to use Markup() to wrap a static translation but escape is better as one can not guarantee the content of a translation. closes odoo/odoo#111850 Related: odoo/documentation#3612 Related: odoo/enterprise#36728 Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
45 lines
1.9 KiB
Python
45 lines
1.9 KiB
Python
# -*- coding: utf-8 -*-
|
|
# Part of Odoo. See LICENSE file for full copyright and licensing details.
|
|
|
|
from markupsafe import Markup
|
|
|
|
from odoo import models, fields, _
|
|
|
|
class Users(models.Model):
|
|
_inherit = 'res.users'
|
|
|
|
odoobot_state = fields.Selection(
|
|
[
|
|
('not_initialized', 'Not initialized'),
|
|
('onboarding_emoji', 'Onboarding emoji'),
|
|
('onboarding_attachement', 'Onboarding attachment'),
|
|
('onboarding_command', 'Onboarding command'),
|
|
('onboarding_ping', 'Onboarding ping'),
|
|
('idle', 'Idle'),
|
|
('disabled', 'Disabled'),
|
|
], string="OdooBot Status", readonly=True, required=False) # keep track of the state: correspond to the code of the last message sent
|
|
odoobot_failed = fields.Boolean(readonly=True)
|
|
|
|
@property
|
|
def SELF_READABLE_FIELDS(self):
|
|
return super().SELF_READABLE_FIELDS + ['odoobot_state']
|
|
|
|
def _init_messaging(self):
|
|
if self.odoobot_state in [False, 'not_initialized'] and self._is_internal():
|
|
self._init_odoobot()
|
|
return super()._init_messaging()
|
|
|
|
def _init_odoobot(self):
|
|
self.ensure_one()
|
|
odoobot_id = self.env['ir.model.data']._xmlid_to_res_id("base.partner_root")
|
|
channel_info = self.env['mail.channel'].channel_get([odoobot_id, self.partner_id.id])
|
|
channel = self.env['mail.channel'].browse(channel_info['id'])
|
|
message = Markup("%s<br/>%s<br/><b>%s</b> <span class=\"o_odoobot_command\">:)</span>") % (
|
|
_("Hello,"),
|
|
_("Odoo's chat helps employees collaborate efficiently. I'm here to help you discover its features."),
|
|
_("Try to send me an emoji")
|
|
)
|
|
channel.sudo().message_post(body=message, author_id=odoobot_id, message_type="comment", subtype_xmlid="mail.mt_comment")
|
|
self.sudo().odoobot_state = 'onboarding_emoji'
|
|
return channel
|