Wednesday, September 2, 2026
1 change · master
Security fixes and vulnerability patches
Email marketing building blocks have been converted to a newer template system, making them easier to update, extend, and maintain across versions. This also reduces security risk from how snippets were previously rendered, adds an easier way to insert unsubscribe links, and prevents product emails from showing internal cost prices.
Original PR description
also modified: html_builder, website Currently, all mailing snippets are "backend" views, instantiated and stored in-database on spin-up, just like website snippets. This has several drawbacks: - mailing snippets cannot be easily updated and/or fixed if they are flawed - new snippets cannot be easily added to older versions - as the snippets are rendered with qweb, they have an elevated level of permission making them an attack vector - "placeholders" for fragments that are editable via plugin (e.g. filling in social links with a company's social info) exist separate from their "filling" This PR intends to fix these issues by turning all backend snippets into frontend Owl templates. To ensure compatibility with the current HTMLBuilder snippet service & existing custom snippets, builtin snippets are seamlessy added to the snippet document when mailing snippets are loaded. task-5477951