make voku/anti-xss an optional package #1728
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This package installs voku/portable-utf8 which "sanitizes" REQUEST_URI in globals, which in turn crashed our entire system.
Library packages should never 'do' anything, just be libraries.
This is:
Checklist:
Why this change is needed?
Our system did break down some time ago after installing voku/portable-utf8 because it sanitizes global variable REQUEST_URI. After that, the package is completely banned from our code base. I don't know if you will accept making it optional (only used one place..), but I will give it a try.