>>>>> "Vivek" == Vivek Khera <[email protected]> writes:

>> As an aside, you really need:
>> 
>> '<img src="';
>> file.name | uri | html;
>> '">';
>> 
>> A file must be URI encoded to get rid of uri-bad chars, then
>> HTML encoded to prepare it for HTML attribute value insertion.
>> 

Vivek> I think the uri escaping is not necessary here -- the browser should
Vivek> worry about that.

No, *you* need to worry about it.  If your filename is

        face of "fred".gif

Then you need to URI-encode that to get

        face%20of%20"fred".gif

and then *that* needs to be HTMLized to get:

        face%20of%20&quot;fred&quot;.gif

-- 
Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<[email protected]> <URL:http://www.stonehenge.com/merlyn/>
Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
See PerlTraining.Stonehenge.com for onsite and open-enrollment Perl training!

_______________________________________________
templates mailing list
[email protected]
http://lists.template-toolkit.org/mailman/listinfo/templates

Reply via email to