I've put a branch to use HTML::Defang on the incoming setting. I'm going to go ahead and slap a pull request on it to improve chances of eyeballs. It has worked in my limited testing, taking script calls in css and commenting them out.
https://git.evergreen-ils.org/?p=working/Evergreen.git;a=commit;h=242ea9f55465c462b66caaf6fc260c4d738d07a3
I've put a branch to use HTML::Defang on the incoming setting. I'm going to go ahead and slap a pull request on it to improve chances of eyeballs. It has worked in my limited testing, taking script calls in css and commenting them out.
https:/ /git.evergreen- ils.org/ ?p=working/ Evergreen. git;a=commit; h=242ea9f55465c 462b66caaf6fc26 0c4d738d07a3