[Notifications] Escape HTML in destUrl and fileName
Ensures that a file or destination named `<h1>foo.txt` doesn't break the layout. It still goes through the normal HTML text filter, so remote file access isn't possible, merely screwing up the layout.
parent
b9593a06
Please register or sign in to comment