On Mar 8, 2013, at 12:13 PM, Jonas Sicking wrote: > On Fri, Mar 8, 2013 at 9:57 AM, Adam Barth <w3c@adambarth.com> wrote: >>> >>> >> >> Even if we had a secure HTML quasi handler, the HTML quasi handler >> would not be the default handler. That means the templating system is >> insecure by default. > > I'm not sure what you mean by "the default one". As I understand it > there's no such thing as a default quasi handler. You always have to > explicitly choose one. > There is no "default handler" but if a template string is not prefixed by a handler tag then its semantics is to simply do string interpolation without observably calling a hander or applying any semantic processing.Received on Friday, 8 March 2013 20:48:47 UTC
This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 17:14:08 UTC