From 0a715d6df5d6d9de8da861dccd1dd5f16e738efc Mon Sep 17 00:00:00 2001 From: Andrey Andreev Date: Mon, 23 Apr 2018 14:33:45 +0300 Subject: [ci skip] Move changelog entry for PR #5391 from 3.1.8 to 3.1.9 Apparently I forgot to cherry-pick the actual change into 3.1-stable --- user_guide_src/source/changelog.rst | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/user_guide_src/source/changelog.rst b/user_guide_src/source/changelog.rst index 36f655182..d2033ac39 100644 --- a/user_guide_src/source/changelog.rst +++ b/user_guide_src/source/changelog.rst @@ -7,6 +7,10 @@ Version 3.1.9 Release Date: Not Released +- **Security** + + - Updated :doc:`URL Helper ` function :php:func:`auto_link()` to add ``rel="noopener"`` to generated links in order to prevent tab hijacking. + - General Changes - Updated :doc:`Query Builder ` method ``limit()`` to allow ``0`` values. @@ -24,7 +28,6 @@ Release Date: Mar 22, 2018 - **Security** - - Updated :doc:`URL Helper ` function :php:func:`auto_link()` to add ``rel="noopener"`` to generated links in order to prevent tab hijacking. - Updated :doc:`Security Library ` method ``xss_clean()`` to also filter JavaScript tag functions. - Fixed a bug where :doc:`Security Library ` method ``xss_clean()`` didn't check for parentheses around JavaScript's ``document``. -- cgit v1.2.3-24-g4f1b