On Thu, 2002-07-18 at 18:01, Pierre van Rooden wrote:
> You use <mm:field name="html(foo)" /> or <mm:field name="html(gui(foo))" />
The point is that you now have to use it almost everywhere.

Why cant the fieldTag itselve do this manipulation since 95% of the
cases in which i use an fieldTag, it has to be html-escaped.

Would you forget this in your page, information can be rendered not
correct, or even worse malicious users could perform cross-side
scripting.

-- 
Eduard Witteveen Systeem Ontwikkelaar
NOS Internet,  Gateway C Kamer 107
+31(0)356772910 http://www.omroep.nl/

Sed quis custodiet ipsos custodes? : The sixth Satire from Juvenal

Reply via email to