W3C home > Mailing lists > Public > w3c-dist-auth@w3.org > January to March 2003

Re: I-D ACTION:draft-ietf-webdav-rfc2518bis-03.txt

From: Roy T. Fielding <fielding@apache.org>
Date: Thu, 13 Mar 2003 11:51:50 -0800
Cc: <w3c-dist-auth@w3.org>
To: "Julian Reschke" <julian.reschke@gmx.de>
Message-Id: <3B5C2F9F-558D-11D7-AB36-000393753936@apache.org>

> known issue.

Good, but that sentence you quoted contradicts it.  XML doesn't
allow subsetting.

> RFC2518bis specifically allows rejection  of requests using external
> entities (this should take care of the "one million laughs" attach).

Recursive entity declarations are internal entities.  :(

Received on Thursday, 13 March 2003 15:49:57 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 2 June 2009 18:44:03 GMT