Drawing text annotation now use the new format functions instead of executing arbitrary code.

This commit is contained in:
Dion Moult
2023-09-07 13:05:03 +10:00
parent de27554043
commit 7bca3bcac3
2 changed files with 4 additions and 3 deletions
+3 -2
View File
@@ -1391,8 +1391,9 @@ class Drawing(blenderbim.core.tool.Drawing):
original_command = command
for variable in re.findall("{{.*?}}", command):
value = ifcopenshell.util.selector.get_element_value(product, variable[2:-2])
command = command.replace(variable, repr(value))
text = text.replace(original_command, str(eval(command[2:-2])))
value = '"' + str(value).replace('"', '\\"') + '"'
command = command.replace(variable, value)
text = text.replace(original_command, ifcopenshell.util.selector.format(command[2:-2]))
for variable in re.findall("{{.*?}}", text):
value = ifcopenshell.util.selector.get_element_value(product, variable[2:-2])
+1 -1
View File
@@ -238,7 +238,7 @@ class IfcCsv:
if row[index] == null:
continue
if not isinstance(row[index], str):
row[index] = '"' + str(row[index]) + '"'
row[index] = '"' + str(row[index]).replace('"', '\\"') + '"'
row[index] = ifcopenshell.util.selector.format(format_query.replace("{{value}}", row[index]))
def sort_results(self, sort, attributes, include_global_id):