https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=40906 --- Comment #28 from Martin Renvoize (ashimema) <martin.renvoize@openfifth.co.uk> --- Created attachment 206866 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=206866&action=edit Bug 40906: (QA follow-up) Escape parameters sent to the Mana server build_request concatenated query parameter values into the outbound URL by hand, with no escaping. A search query or sort value containing &, #, or = would inject extra parameters into (or corrupt) the request sent to Mana. Use URI's query_form to build the query string instead, which percent-encodes values. Scoped to the 'get'/'getwithid' branches used by search_entities and get_entity_by_id, the two entry points exercised by the new /mana/reports endpoint and report-details page. Verified against t/db_dependent/Koha/SharedContent.t and against a local koha-mana test instance. Signed-off-by: Martin Renvoize <martin.renvoize@openfifth.co.uk> -- You are receiving this mail because: You are watching all bug changes.