W3C home > Mailing lists > Public > whatwg@whatwg.org > April 2007

[whatwg] Parsing: < in unquoted attribute values

From: Anne van Kesteren <annevk@opera.com>
Date: Thu, 26 Apr 2007 08:59:58 +0200
Message-ID: <op.trdpp8xz64w2qv@id-c0020>
On Thu, 26 Apr 2007 02:17:12 +0200, Jonas Sicking <jonas at sicking.cc> wrote:
> We do no longer support this in mozilla (if we ever did). A reason we  
> now explicitly forbid this is we don't want it to ever be possible to  
> create elements with 'illegal' names. Same thing goes for attribute  
> names. This is partially for security reasons since some elements and  
> attributes carry very important security information.

Could you elaborate on the security issues? Could you also give a  
definition of "illegal names" as it's not really clear to me what that  
means for HTML.

> I fully agree with Simons original proposal though.

Anne van Kesteren
Received on Wednesday, 25 April 2007 23:59:58 UTC

This archive was generated by hypermail 2.4.0 : Wednesday, 22 January 2020 16:58:54 UTC