fff31b316f5abd314f5a3eba291fc0e95aedbb71
Since [1], it's possible to conditionnally bypass the HTML sanitizer in field definition with the `sanitize_overridable` attribute. In a nutshell, when someone is part of the required group(s), it won't go through the sanitizer, while the people not part of the group(s) will. A behavior was thus introcuded to prevent a "restricted" user to wipe the changes done previously by an "elevated" user (which bypassed the sanitizer). But that behavior was not correct as there was unforeseen cases which led to raise this error which are not due to the sanitizer but to normalization. Indeed, while named `html_sanitize()`, it also does some normalize stuff on top of the real sanitize part. For instance, there is also (not exhaustive): - some MAKO compatibility, replacing some chars - special case for quotes, related to mail clients, which will add data attributes, add nodes in dom etc. This happen when the following are found: - `<blockquote/>` tag - text-based quotes (>, >>) and signatures (-- Signature) - html signature (-- <br />blah) - some editor compatibility which removed the wrapping `<div/>` element - `nbsp` handling.. See commit list below for detail about how/when/why those normalize cases where introduced. At the end, the issue was that the normalize part should not prevent a "restricted" user to modify the content of an "elevated" user. Only the sanitize part should. For instance, the `Quotes` snippet dropped by an "elevated" user was preventing further edition by a "restricted" user because there was a "false positive" raised when checking if the save would wipe the existing changes. Indeed, when the "elevated" user droped the snippet, it was saved as: ```html <blockquote class=".." data-name="Blockquote"> ``` But when the "restricted" user then wanted to do some changes, it would become: ```html <blockquote class=".." data-name="Blockquote" data-o-mail-quote-node="1" data-o-mail-quote="1"> ``` Same for `Share` snippet: ```html <a href="https://www.facebook.com/sharer/sharer.php?u={url}"> <a href="https://www.facebook.com/sharer/sharer.php?u=%7Burl%7D"> ``` [1]: https://github.com/odoo/odoo/commit/cf844e34dd0ce4830eb99fd0fa5b6b9cb58c867c Normalize commit list: https://github.com/odoo/odoo/commit/5f1ec49ecdac6d72cd42755c41fbe75d6a1f3587 https://github.com/odoo/odoo/commit/69af79ff3d705d19a71ba3ba7851b981cb301077 https://github.com/odoo/odoo/commit/2bcf4cca79a57dfba84d1f3e3fa7b8908bfe66e8 https://github.com/odoo/odoo/commit/f5688cd8fd515d1b668e8eb1d74de68faa681a01 https://github.com/odoo/odoo/commit/cb8c2d2b7e15c7c16e02d078767e27a07e5012c6 https://github.com/odoo/odoo/commit/275ee5825d38841a3eb21bb195722f3ceed09005 https://github.com/odoo/odoo/commit/b51d21c5b83b88e8d56dbbbb7600bcbe554d1b07 closes odoo/odoo#110903 X-original-commit: 3a2e82cf40f3265650b4f79f9ad5fe309906311d Signed-off-by: Romain Derie (rde) <rde@odoo.com>
…
…
Odoo
Odoo is a suite of web based open source business apps.
The main Odoo Apps include an Open Source CRM, Website Builder, eCommerce, Warehouse Management, Project Management, Billing & Accounting, Point of Sale, Human Resources, Marketing, Manufacturing, ...
Odoo Apps can be used as stand-alone applications, but they also integrate seamlessly so you get a full-featured Open Source ERP when you install several Apps.
Getting started with Odoo
For a standard installation please follow the Setup instructions from the documentation.
To learn the software, we recommend the Odoo eLearning, or Scale-up, the business game. Developers can start with the developer tutorials
Languages
Python
49.6%
JavaScript
47.8%
SCSS
2%
CSS
0.3%
HTML
0.2%