mirror of
https://github.com/discourse/discourse.git
synced 2025-02-21 03:19:10 +00:00
This isn't a security bug, because only admins can create user fields and we have to trust admins, because they can change themes, which are shown site-wide and can contain unrestricted JS.