You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Developer manual: add crypto APIs, unserialize and CSV injection to security.rst #15681
developer_manual/digging_deeper/security.rstis missing a few basics, and one example uses private API.OCP\Security\ICrypto,ISecureRandomandIHasher(currently only listed in the DI docs).unserialize()user-influenced data, use JSON".=,+,-or@(formula injection).ITrustedDomainHelperexample (around line 102) uses\OC::$server->get(), which is private. Show constructor injection instead.