-
Suggestion
-
Resolution: Fixed
-
None
With the implementation of CONF-9627 we should move to enable the automatic HTML entity encoding behaviour by default. Once this is done and developers are happy with the outcome, we can start removing the explict calls to htmlEncode in earnest.
- is blocked by
-
CONFSERVER-14129 Exporting to Word in anti-XSS mode will include html tags
- Closed
- relates to
-
CONFSERVER-9627 Velocity does not automatically escape HTML entities when substituting variables
- Closed
-
CONFSERVER-14431 Write Anti-XSS documentation for plugin developers
- Closed