prologue/security.rst still teaches removed APIs: the SQL injection section uses \OCP\DB::prepare and Mapper execute, the JavaScript section is jQuery-era with nothing on Vue / v-html, and the auth bypass section relies on OCP\JSON::checkLoggedIn(). (The directory traversal example is fixed in #15678.)
prologue/security.rststill teaches removed APIs: the SQL injection section uses\OCP\DB::prepareand Mapperexecute, the JavaScript section is jQuery-era with nothing on Vue /v-html, and the auth bypass section relies onOCP\JSON::checkLoggedIn(). (The directory traversal example is fixed in #15678.)