Escape dynamic error messages with htmlspecialchars() before concatenating into HTML strings stored in validation_logs. Add a Purify-based mutator on Server model as defense-in-depth, with a dedicated HTMLPurifier config that allows only safe structural tags. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| CaCertificate | ||
| CloudProviderToken | ||
| New | ||
| PrivateKey | ||
| Proxy | ||
| Security | ||
| Advanced.php | ||
| Charts.php | ||
| CloudflareTunnel.php | ||
| Create.php | ||
| Delete.php | ||
| Destinations.php | ||
| DockerCleanup.php | ||
| DockerCleanupExecutions.php | ||
| Index.php | ||
| LogDrains.php | ||
| Navbar.php | ||
| Proxy.php | ||
| Resources.php | ||
| Sentinel.php | ||
| Show.php | ||
| Swarm.php | ||
| ValidateAndInstall.php | ||