cleodora icon indicating copy to clipboard operation
cleodora copied to clipboard

cleosrv: Automatically ensure all textual input is HTML escaped to prevent XSS

Open omarkohl opened this issue 2 years ago • 1 comments

It's already the case for forecast creation, but it's easy to forget when adding new operations. Ideally it should be the default for any textual input. In a later increment it might be desirable to allow for some safe HTML so people can style e.g. the forecast description. Alternatively supporting markdown would be great.

omarkohl avatar Jan 04 '23 08:01 omarkohl

Related to #257

omarkohl avatar May 25 '23 06:05 omarkohl