4fdd0ed728
- It's possible for reviews to not be assiocated with users, when they
were migrated from another forge instance. In the migration code,
there's no sanitization check for author names, so they could contain
HTML tags and thus needs to be properely escaped.
- Pass `$reviewerName` trough `Escape`.
(cherry picked from commit
|
||
---|---|---|
.. | ||
add_reaction.tmpl | ||
attachments.tmpl | ||
comments.tmpl | ||
comments_delete_time.tmpl | ||
context_menu.tmpl | ||
pull.tmpl | ||
pull_merge_instruction.tmpl | ||
reactions.tmpl | ||
reference_issue_dialog.tmpl | ||
sidebar.tmpl | ||
update_branch_by_merge.tmpl |