- Issue created by @Ruuds
- last update
9 months ago 6 pass - Status changed to Needs review
9 months ago 9:47am 13 May 2024 - 🇳🇱Netherlands Ruuds
The test failures are not related. The tests are broken anyway.
- Status changed to RTBC
9 months ago 7:12am 14 May 2024 - 🇩🇪Germany spuky
looks good to me json encode is the for sure the better way to go...
- Status changed to Needs work
8 months ago 3:13pm 8 June 2024 - leymannx Berlin
A single
json_encode($value)
without any flag also is not enough. You need at leastjson_encode($value, JSON_UNESCAPED_SLASHES)
to prevent slashes in the URLs being escaped. - Assigned to leymannx
- last update
8 months ago 6 pass - last update
8 months ago 6 pass - Status changed to Needs review
8 months ago 6:38pm 8 June 2024 - Issue was unassigned.
- last update
7 months ago 7 pass - last update
7 months ago 7 pass - Status changed to Fixed
7 months ago 11:46am 27 June 2024 - leymannx Berlin
Yeah, I think we've just fixed the related issue as well. json_encode together with the constants we use makes it quite safe against XSS.
Automatically closed - issue fixed for 2 weeks with no activity.