falue / szenodb

Forum for art dep workers in the film & theater industry to share knowledge.
https://szenodb.ch
GNU General Public License v3.0
0 stars 0 forks source link

sanitize every user input field before saving #77

Open falue opened 1 year ago

falue commented 1 year ago

stripHtml()

falue commented 1 year ago

Or never use v-html with user input text?-> only used in viewresource data.content.title and data.content.name

falue commented 1 year ago

never used v-html