Re: [encoding] iso-2022-jp encoder XSS risks (#15)

What about my suggestion for encoding the byte 0x1A whenever a U+000E, U+000F or U+001B is passed to it?
  
Alternatively, would it be acceptable to specify encoding the HTML escape and/or making use of the error mode _in the encoder itself_ rather than at a higher level?

---
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/encoding/issues/15#issuecomment-174695847

Received on Monday, 25 January 2016 22:20:08 UTC