Subject: | filters will not apply to objects |
Trying to apply a filter to an object will silently ignore the filter. For example, a URI object overloads "" and can usefully appear in a template. Trying to apply an html filter to it will ignore the filter, which may result in XSS flaws. This also applies to AUTO_FILTER.