Re: preventing script injection

2007-04-12 Thread Trevor Jim
Robert Sayre wrote: > > As Brendan points out, you can't rely on web server applications to > correctly parse HTML at this point. I agree, and I think that our sandbox implementation does a good job of avoiding this problem. I'll hold off on commenting on the proposal until I see the details.

Re: preventing script injection

2007-04-12 Thread Gervase Markham
Brendan Eich wrote: > I'm not kidding, and I'm not saying some web developers should not have > the ability to script filtering of user-generated content. The expertise > to do this well, and to track evolving browser features, is rare. Possibly true. But so is the ability to write decent and we