Skip to content

Security Patch

Choose a tag to compare

@jstrimpel jstrimpel released this 15 Apr 17:15
  • Don't list directory contents by default
  • Clone parameters when passed from parent controller to child controller
  • Encode parameters serialized in first page response and decode during rehydration to prevent XSS attacks