Encode this before showing it.
Encode parameters before showing them to users.
Encode some more parameters before showing them to users.
Encode the interface parameter before using it in a redirect
Encode the if parameter before using it in redirects, too.
Conflicts:
usr/local/www/firewall_rules.php
Encode the if parameter before using it in html
Escape parameters better when managing tables. Fix test to allow deleting subnet entries as well as IPs.
usr/local/www/diag_tables.php
Remove debug output
Set the CSRF Magic timeout to the same as the session timeout, so that if a user sets a lower session time, the CSRF magic tokens do not outlive the user's session.
Update CSRF Magic
View revisions
Also available in: Atom