fix: escape title output to prevent XSS#3669
Conversation
📝 WalkthroughWalkthroughEscaped multiple outputs in post rendering to prevent XSS: title, category link hrefs and labels, meta separator, datetime attributes and displayed dates, and comments count. No control-flow or public API changes; changes are output-escaping only. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches
📜 Recent review detailsConfiguration used: defaults Review profile: CHILL Plan: Pro 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🤖 Pull request artifacts
|
Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.