Skip to content
This repository was archived by the owner on Feb 16, 2026. It is now read-only.

fix(security): Do not echo the entered value back to the user.#467

Merged
cafuego merged 2 commits intodevfrom
cafuego/hid-2436-avoids-xss
Aug 4, 2025
Merged

fix(security): Do not echo the entered value back to the user.#467
cafuego merged 2 commits intodevfrom
cafuego/hid-2436-avoids-xss

Conversation

@cafuego
Copy link
Copy Markdown
Contributor

@cafuego cafuego commented Aug 1, 2025

This way we avoid a potential XSS, which I must say I am not able to reproduce. HID tells me to go awya when I try to inject some script intp the email field. Still, better safe than sorry.

Refs: HID-2436

This way we avoid a potential XSS, which I must say I am not able to reproduce. HID tells me to go awya when I try to inject some script intp the email field. Still, better safe than sorry.

Refs: HID-2436
@cafuego cafuego requested review from attiks and orakili August 1, 2025 05:17
@cafuego cafuego merged commit 8e83cad into dev Aug 4, 2025
1 check passed
@cafuego cafuego deleted the cafuego/hid-2436-avoids-xss branch August 4, 2025 23:00
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants