forgejo/templates/repo/issue/view_content
Gusted ca798e4cc2
[SECURITY] Test XSS in dismissed review
It's possible for reviews to not be assiocated with users, when they
were migrated from another forge instance. In the migration code,
there's no sanitization check for author names, so they could contain
HTML tags and thus needs to be properely escaped.
2024-02-22 15:33:20 +01:00
..
add_reaction.tmpl
attachments.tmpl
comments.tmpl
comments_delete_time.tmpl
context_menu.tmpl
conversation.tmpl
pull.tmpl
pull_merge_instruction.tmpl
reactions.tmpl
reference_issue_dialog.tmpl
show_role.tmpl
sidebar.tmpl
update_branch_by_merge.tmpl
watching.tmpl