* Fixes unescaped user output in JavaScript API mode (potential reflected XSS)
* No security advisory because this is only an RC module
* Updating is always recommended but you don't have to update to rc8 unless you are using rc6 or rc7 and the JavaScript API mode
Passed errors from the gateway back to the user instead of simply logging it as a failed payment. This means the user now cannot complete the checkout unless their payment is successful.