Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Not marking msg as html_safe by default. #868

Merged
merged 1 commit into from
Aug 9, 2015

Commits on Aug 7, 2015

  1. Not marking msg as html_safe by default.

    This could be misused as attack vector for xss attacks.
    Added two tests for checking the behavior for the two cases if user
    escapes message or not.
    panmari committed Aug 7, 2015
    Configuration menu
    Copy the full SHA
    f870d3a View commit details
    Browse the repository at this point in the history