You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I recommend that some pages / areas of the docs of v3 and v4, and even in future versions, should be updated with some kind of note / warning of not using or not be on the escape_html or $smarty->default_modifiers without a this option: ['escape:"htmlall"'] in order to help to prevent XSS attacks and use security good practice.
Example of some pages / areas in v4 docs:
Getting started page
in designers > language-basic-syntax > Introduction page
in designers > language-variables > Introduction page
in designers > language-modifiers > Introduction page
in designers language-modifiers > Introduction page
The text was updated successfully, but these errors were encountered:
ampmonteiro
changed the title
[DOCS] Add note / warning about escape html / modifier
[Docs] Add note / warning about escape html / modifier
Mar 6, 2023
ampmonteiro
changed the title
[Docs] Add note / warning about escape html / modifier
[Docs] Add note / warning of not using escape html / modifier
Mar 6, 2023
ampmonteiro
changed the title
[Docs] Add note / warning of not using escape html / modifier
[Docs] Add note / warning of not using escape htm settingl / modifier
Mar 6, 2023
ampmonteiro
changed the title
[Docs] Add note / warning of not using escape htm settingl / modifier
[Docs] Add note / warning of not using escape html settingl / modifier
Mar 6, 2023
Hi
in sequence of issue #863 .
I recommend that some pages / areas of the docs of v3 and v4, and even in future versions, should be updated with some kind of note / warning of not using or not be on the
escape_html
or$smarty->default_modifiers
without a this option:['escape:"htmlall"']
in order to help to prevent XSS attacks and use security good practice.Example of some pages / areas in v4 docs:
Getting started
pageIntroduction
pageIntroduction
pageIntroduction
pageIntroduction
pageescape
pageunescape
pageThe text was updated successfully, but these errors were encountered: