- From: Adam Barth <w3c@adambarth.com>
- Date: Tue, 9 Dec 2008 14:06:55 -0800
- To: "Marcos Caceres" <marcosscaceres@gmail.com>
- Cc: "Jonas Sicking" <jonas@sicking.cc>, "Simon Pieters" <simonp@opera.com>, "Laurens Holst" <lholst@students.cs.uu.nl>, public-webapps <public-webapps@w3.org>
On Tue, Dec 9, 2008 at 12:42 PM, Marcos Caceres <marcosscaceres@gmail.com> wrote: > If authors want to use "application/xml", > then they can use <content src="somefile" type="application/xml" /> > and hope for the best :) I haven't been following the widget discussion very closely, so I apologize if this issue is understood already, but, in general, being able to coerce an arbitrary URL to application/xml is a big security problem. Can you point me to where the <content> tag is defined? Thanks, Adam
Received on Tuesday, 9 December 2008 22:14:33 UTC