W3C home > Mailing lists > Public > public-xml-processing-model-wg@w3.org > June 2007

Re: Revised parameters proposal

From: Alessandro Vernet <avernet@orbeon.com>
Date: Thu, 7 Jun 2007 12:28:54 +0200
Message-ID: <4828ceec0706070328h88ac4d4n78647bce79c3c0f7@mail.gmail.com>
To: public-xml-processing-model-wg <public-xml-processing-model-wg@w3.org>

On 6/6/07, Norman Walsh <ndw@nwalsh.com> wrote:
> 4. One case that we expect to be common is that a pipeline has no
>    explicit parameters but that user-specified top-level
>    parameters should be passed to steps.

I don't think it is a good idea for the pipeline engine to hand on by
default parameters passed to the pipeline to components called in the
pipeline. This may permit someone calling a pipeline to pass
parameters that influence components called by the pipeline in a way
that is not intended by the pipeline author, potentially posing a
security risk.

Alex
-- 
Orbeon Forms - Web 2.0 Forms, open-source, for the Enterprise
http://www.orbeon.com/
Received on Thursday, 7 June 2007 10:29:02 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 8 January 2008 14:21:53 GMT