While not encoding the HTML tags in the JSON response is perfectly fine since we set the proper mimetype as well as disable content sniffing a lot of automated code scanner do report this as security bug. Encoding them leads to less discussions and a lot of saved time. |
||
|---|---|---|
| .. | ||
| db | ||
| http | ||
| utility | ||
| apicontroller.php | ||
| app.php | ||
| controller.php | ||
| http.php | ||
| iapi.php | ||
| iappcontainer.php | ||
| middleware.php | ||
| ocscontroller.php | ||
| queryexception.php | ||