mirror of
https://github.com/discourse/discourse.git
synced 2025-03-09 14:34:35 +00:00
This isn't a security bug, because only admins can create user fields and we have to trust admins, because they can change themes, which are shown site-wide and can contain unrestricted JS.