Closed
Description
From https://github.com/adoconnection/RazorEngineCore/wiki/@Raw
By default, RazorEngine will not encode values to be HTML safe, you need to escape values by yourself
I think this is a security issue. It's really unexpected and I'm sure many won't see this warning at all.
Please change the default in the next major version
Metadata
Metadata
Assignees
Labels
No labels