Earlier commits in this branch dropped reflected user input from
ajaxError() messages entirely to close Snyk XSS findings, but that
lost useful diagnostic information ("Unrecognised action <name>",
"Insufficient permissions for user <user>"). Use validHtmlStr()
(htmlspecialchars with ENT_QUOTES) so the values still appear in
the message and Snyk recognises the sanitization. Affects
add_monitors.php, device.php, event.php, events.php, log.php.
Both ajaxError() calls in device.php concatenated user-controlled
data ($_REQUEST['action'], $user->Username()) into the response
body. exit(jsonEncode(...)) is flagged by Snyk regardless of
Content-Type. Drop the reflected tokens; still log the action
server-side via ZM\\Warning.