cuba-platform / documentation

CUBA Platform Documentation
https://www.cuba-platform.com
Creative Commons Attribution 4.0 International
26 stars 45 forks source link

Security implications of RichTextArea (sanitize value to avoid XSS) #658

Open web-devel opened 4 years ago

web-devel commented 4 years ago

Until cuba-platform/cuba/issues/2703 is resolved, recommend to sanitize value of RichTextArea by default.

Also see https://vaadin.com/docs/v8/framework/advanced/advanced-security.html#advanced.security.sanitizing