Joerg Heinicke wrote:
Nacho (Derecho.com) wrote:
"{request:translate('{1}','-','')}"

the user might go to: http://localhost:8080/b/hello',nasty.java.call(),'world

It's JXPath, not JXTemplate. Does it evaluate Java calls at all?
If your example really works, http://localhost:8080/b/nasty.java.call() will as well.

To be honest I don't know what JXPath can and cannot evaluate
(Java calls? any extensions to XPath? Java objects? request and session objects?)

I just saw some bad/unusual quotation {request:translate('{1}','-','')} and I thought I'd alert against possible problems. But maybe I'm wrong.


Tobia

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to