mirror of
https://github.com/zadam/trilium.git
synced 2026-01-08 16:32:13 +01:00
see also https://api.jquery.com/html/ under "Additional Notes": "Do not use these methods to insert strings obtained from untrusted sources such as URL query parameters, cookies, or form inputs. Doing so can introduce cross-site-scripting (XSS) vulnerabilities. Remove or escape any user input before adding content to the document. " fixes #1072