Thank you for your great add-on. But I think you should add h() functions in the generated view.php files to sanitize user inputs.

<?php  if (isset($textbox) && trim($textbox) != ""){ ?>
<?php  echo h($textbox); ?>
<?php  } ?>

Please reconsider this.
Thanks again!

ramonleenders replied on at Permalink Reply

Thanks for you input on this. Can you explain to me what this does and the advantages over just echo'ing the input without calling this function? I mean, are you having troubles without calling this function? What could go wrong in scenarios? I'm willing to implement this of course, if I have reason to.

Kind regards,

hissy replied on at Permalink Reply
The only reason is security. Escaping some special characters with the h function will reduce the risks of XSS.
ramonleenders replied on at Permalink Reply
Hi Hissy,

Escaping output for text_box, text_area and email field types will do I assume? The rest of the fields got validation OR needs formatting (like WYSIWYG). Agree?

Kind regards,

hissy replied on at Permalink Reply
Yes, I agree that.

