For header() calls that happen outside of Cake's scope, we should wrap them in a function to ensure proper escaping. This is currently done on a case-by-case basis, but for new header() calls we should consider centralizing.
Per morgamic - he wants it closed.
Nice job everyone.
(In reply to comment #2) > Nice job everyone. That's what.... nevermind.