Fix for security bug DRUPAL-SA-CONTRIB-2015-163, which allowed nodes placed into a recycle bin to remain accessible by the same users who could access them when outside of the bin.
* Fixes unescaped user output in JavaScript API mode (potential reflected XSS)
* No security advisory because this is only an RC module
* Updating is always recommended but you don't have to update to rc8 unless you are using rc6 or rc7 and the JavaScript API mode