Re: [encoding] iso-2022-jp encoder XSS risks (#15)

Only from the start and end of the URL. If we return U+FFFD, that ends up being emitted as an "HTML entity" but I suppose that's fine. @hsivonen, any thoughts on also having that treatment for U+000E and U+000F?

---
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/encoding/issues/15#issuecomment-174495197

Received on Monday, 25 January 2016 12:41:53 UTC