Skip to content

Conversation

@dinaweiwendi
Copy link

Autoescape protects web applications against most common cross-site-scripting (XSS) vulnerabilities.
While the output from Jinja templates in the Kafka module don't generate HTML, enabling autoescape for HTML/XML avoids tripping automatic security scanners.

Commit Message: Autoescape protects web applications against most common cross-site-scripting (XSS) vulnerabilities.
While the output from Jinja templates in the Kafka module don't generate HTML, enabling autoescape for HTML/XML avoids tripping automatic security scanners.
Additional Description: Related pr #38711
Risk Level: low
Testing: n/a, "Tests will automatically run for you."
Docs Changes: n/a
Release Notes: n/a
Platform Specific Features: n/a
[Optional Runtime guard:]
[Optional Fixes #Issue]
[Optional Fixes commit #PR or SHA]
[Optional Deprecated:]
[Optional API Considerations:]

Autoescape protects web applications against most common
cross-site-scripting (XSS) vulnerabilities.
While the output from Jinja templates in the Kafka module don't
generate HTML, enabling autoescape for HTML/XML avoids tripping
automatic security scanners.

Signed-off-by: Dina Di <[email protected]>
@repokitteh-read-only
Copy link

Hi @dinaweiwendi, welcome and thank you for your contribution.

We will try to review your Pull Request as quickly as possible.

In the meantime, please take a look at the contribution guidelines if you have not done so already.

🐱

Caused by: #42672 was opened by dinaweiwendi.

see: more, trace.

@mathetake
Copy link
Member

sorry could you clarify on exactly what do you want to achieve with this? These configs are harmless but not used by Envoy binary in practice

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants