Escape dynamic error messages with htmlspecialchars() before concatenating into HTML strings stored in validation_logs. Add a Purify-based mutator on Server model as defense-in-depth, with a dedicated HTMLPurifier config that allows only safe structural tags. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| api.php | ||
| app.php | ||
| auth.php | ||
| broadcasting.php | ||
| cache.php | ||
| chunk-upload.php | ||
| constants.php | ||
| cors.php | ||
| database.php | ||
| debugbar.php | ||
| filesystems.php | ||
| fortify.php | ||
| hashing.php | ||
| horizon.php | ||
| livewire.php | ||
| logging.php | ||
| mail.php | ||
| purify.php | ||
| queue.php | ||
| ray.php | ||
| sanctum.php | ||
| sentry.php | ||
| services.php | ||
| session.php | ||
| subscription.php | ||
| telescope.php | ||
| testing.php | ||
| view.php | ||