mirror of
https://github.com/discourse/discourse.git
synced 2026-03-03 23:54:20 +08:00
There was no security issue associated with this as it would require a very complex and almost impossible setup to exploit it, still, it's a cleaner pattern to escape the user provided value here. |
||
|---|---|---|
| .. | ||
| confirm_email.html.erb | ||
| index.html.erb | ||
| register.html.erb | ||
| resend_email.html.erb | ||
| setup_discourse_id.html.erb | ||