Re: [Content Security Policy] Proposal to move the debate forward

On 27 January 2011 22:42, Michal Zalewski <lcamtuf@coredump.cx> wrote:

> Many people proposed this, and it's a superior alternative on many
> counts, but I think that nobody figured out a nice way to do this that
> would be at least sort-of XML-compatible - and that's a
> deal-breaker...
>

You've lost me there. Why could it not be made compatible with XML?
All you need is a start and end it doesn't matter the format, once a start
and end is defined the parser would start looking for the tokens first and
any invalid injections inside could be removed or prevented from overlapping
with other markers.

Received on Thursday, 27 January 2011 22:52:42 UTC