Skip to content

Commit

Permalink
Item13301: spelling
Browse files Browse the repository at this point in the history
  • Loading branch information
cdot committed Mar 9, 2015
1 parent ec3fdd1 commit 0ffe965
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions core/data/System/VarQUERYPARAMS.txt
@@ -1,7 +1,7 @@
%META:TOPICINFO{author="ProjectContributor" date="1417320330" format="1.1" version="1"}%
%META:TOPICINFO{author="ProjectContributor" date="1425913636" format="1.1" version="1"}%
%META:TOPICPARENT{name="Macros"}%
#VarQUERYPARAMS
---+++ QUERYPARAMS -- show paramaters to the query
---+++ QUERYPARAMS -- show parameters to the query
* Expands the parameters to the query that was used to display the page.
* Syntax: =%<nop>QUERYPARAMS{...}%=
* Supported parameters:
Expand All @@ -22,6 +22,6 @@
}%</pre>
<div class="foswikiHelp">%X% *Security warning!*

Using QUERYPARAMS can easily be misused for cross-site scripting unless specific characters are entity encoded. By default QUERYPARAMS encodes the characters ='"&lt;&gt;%= into HTML entities (same as encoding="safe") which is relatively safe. The safest is to use encoding="entity". When passing QUERYPARAMS inside another macro always use double quotes ("") combined with using QUERYPARAMS with encoding="quote". For maximum security against cross-site scripting you are adviced to install the Foswiki:Extensions.SafeWikiPlugin.</div>
Using QUERYPARAMS can easily be misused for cross-site scripting unless specific characters are entity encoded. By default QUERYPARAMS encodes the characters ='"&lt;&gt;%= into HTML entities (same as encoding="safe") which is relatively safe. The safest is to use encoding="entity". When passing QUERYPARAMS inside another macro always use double quotes ("") combined with using QUERYPARAMS with encoding="quote". For maximum security against cross-site scripting you are advised to install the Foswiki:Extensions.SafeWikiPlugin.</div>
* See also [[VarQUERYSTRING][QUERYSTRING]], [[%IF{"'%INCLUDINGTOPIC%'='Macros'" then="#"}%VarURLPARAM][URLPARAM]]
<!--%JQREQUIRE{"chili"}%-->

0 comments on commit 0ffe965

Please sign in to comment.