517 B
517 B
effect
| effect |
|---|
| patch |
Harden HttpApi documentation HTML rendering.
Scalar descriptions and CDN versions were interpolated without attribute-safe escaping. Embedded OpenAPI JSON in Scalar and Swagger also handled only the exact </script> sequence, not other valid script end-tag forms.
Attribute values and CDN versions are now encoded for their contexts, and embedded JSON escapes < so it cannot close its script element.