You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I think it'd be useful if it the docs made it obvious which fields can have untrusted input in them, because otherwise users might set themselves up for injection attacks.
The text was updated successfully, but these errors were encountered:
How do you define untrusted input here? I guess there are places where construct selectors based on user strings (Form in particular), and in those cases I suspect the solution is actually to do the appropriate escaping instead of just add a warning on those methods?
I think it'd be useful if it the docs made it obvious which fields can have untrusted input in them, because otherwise users might set themselves up for injection attacks.
The text was updated successfully, but these errors were encountered: