Commit eeee3b1
committed
FOUR-29250 Document element-destination redirect risk; strip remember_token from Mustache context
- Add docblock in ProcessRequestToken for medium-risk redirect/Mustache behavior
- Unset _user.remember_token in getElementDestinationMustacheContext (defense in depth)
- Document in ConditionalRedirectService that normalizeDataForFeel changes comparison semantics1 parent 74212c5 commit eeee3b1
1 file changed
Lines changed: 5 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1466 | 1466 | | |
1467 | 1467 | | |
1468 | 1468 | | |
| 1469 | + | |
| 1470 | + | |
| 1471 | + | |
| 1472 | + | |
| 1473 | + | |
1469 | 1474 | | |
1470 | 1475 | | |
1471 | 1476 | | |
| |||
0 commit comments