Escape voice-derived attributes in Azure TTS SSML

The Azure TTS handler (_tts_azure) interpolated the user-supplied voice,
and the locale derived from it, into the SSML xml:lang and <voice name>
attributes without XML-escaping, while the text body was already escaped
(2e75c6dbd). Escape both attributes too, so every user-derived value in
the SSML document is consistently encoded.

Co-authored-by: alanturing881 <alanturing881@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Classic298 2026-06-06 19:21:50 +02:00
parent b1d40f3409
commit 0ac23788f1

View file

@ -467,8 +467,8 @@ async def _tts_azure(request, payload, file_path, file_body_path, user):
output_format = request.app.state.config.TTS_AZURE_SPEECH_OUTPUT_FORMAT
ssml = (
f'<speak version="1.0" xmlns="http://www.w3.org/2001/10/synthesis" xml:lang="{locale}">'
f'<voice name="{language}">{html.escape(payload["input"])}</voice>'
f'<speak version="1.0" xmlns="http://www.w3.org/2001/10/synthesis" xml:lang="{html.escape(locale)}">'
f'<voice name="{html.escape(language)}">{html.escape(payload["input"])}</voice>'
f'</speak>'
)