Skip to content
Extraits de code Groupes Projets
  1. mai 24, 2014
    • Jonne Haß's avatar
      Render flash message content with .text · ecb1b80e
      Jonne Haß a rédigé
      .html does not escape any html input in these, leading to XSS
      attack vectors.
      
      Thanks to A Kai (@sixhundredns) for reporting the related issues.
      ecb1b80e
    • Jonne Haß's avatar
      Remove hack from exporter · d36589e0
      Jonne Haß a rédigé
      I couldn't reproduce what the comment states anymore, so I just removed
      it. This fixes a minor issue where html wouldn't be escaped in the
      export.
      
      Thanks to A Kai (@sixhundredns) for reporting.
      d36589e0
  2. mai 23, 2014
  3. mai 22, 2014
  4. mai 20, 2014
  5. mai 18, 2014
  6. mai 17, 2014
  7. mai 16, 2014
  8. mai 15, 2014
Chargement en cours