Commit e3bf421
committed
minor #21409 Escape user data in server-data.rst (dave1010)
This PR was merged into the 6.4 branch.
Discussion
----------
Escape user data in server-data.rst
Escape user data for HTML attributes to prevent XSS.
This is already done in the second code snippet below.
Twig playground demo:
https://twig.symfony.com/play?data=eyJ0ZW1wbGF0ZXMiOltbImluZGV4LnR3aWciLCI8ZGl2IGRhdGEtZm9vPVwiTm90IGVuY29kZWQge3sgbmFtZXxqc29uX2VuY29kZSB9fVwiPlxuXG48ZGl2IGRhdGEtZm9vPVwiRW5jb2RlZCB7eyBuYW1lfGpzb25fZW5jb2RlfGUoJ2h0bWxfYXR0cicpIH19XCI%2BIl1dLCJjb250ZXh0Ijp7Im5hbWUiOiJXb3JsZCJ9LCJ2ZXJzaW9uIjoiMy4yMS4xIiwib3B0aW9ucyI6eyJzdHJpY3RfdmFyaWFibGVzIjp0cnVlLCJjaGFyc2V0IjoiVVRGLTgiLCJhdXRvZXNjYXBlIjoiIn19
Commits
-------
fb0b35d Escape user data in server-data.rst1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| 13 | + | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| |||
0 commit comments