WoltLab / docs.woltlab.com

GNU Lesser General Public License v2.1
19 stars 18 forks source link

Document the unsafe prefix #426

Closed BurntimeX closed 4 months ago

BurntimeX commented 4 months ago

This PR intentionally removes a lot of unnecessary uses of the @ operator. Having a few more calls to htmlspecialchars() makes no difference, but avoids potential security issues now or in the future, for example, when performing refactors.

Closes #424