https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=43570 --- Comment #14 from Martin Renvoize (ashimema) <martin.renvoize@openfifth.co.uk> --- QA follow-up: attached two small patches building on the signed-off/passed fix, addressing David's two comments (#7 and #8) which were never followed up on: 1) Bug 43570: (QA follow-up) Guard weaken() against non-ref/already-weak _CONTEXT Mirrors the guard Template-Toolkit itself uses from 2.29 onwards (weaken(...) if ref ... && !isweak ...) instead of the bare weaken() copied from the 2.28 fix. Confirmed calling weaken() twice on the same slot is a safe no-op with the Scalar::Util shipped here, so this isn't fixing a live bug - just bringing us in line with upstream's own defensive style. 2) Bug 43570: (QA follow-up) Make SafeURL a static filter SafeURL's filter() never reads $args/$config, so _DYNAMIC = 1 isn't needed there (HtmlScrubber genuinely needs it for its 'type' config arg). Verified the filter still works correctly as static (same test suite + a manual render check). Both are small, low-risk, isolated commits on top of the existing signed-off fix - not blocking, just tidying up before this ships. Re-ran the full test suite and koha-qa.pl across all 4 commits, all green. -- You are receiving this mail because: You are watching all bug changes.