Re: HTML Security Issue

Hi Edward,

Nice Idea but what if the user put's in "&amp" 
you can't tell the difference between that and what came 
out of the database. So if you convert it when going into the
database you get "&amp" and then "&amp" etc 

Jeff Sinclair

>
>Why not also convert '&' characyters entered by the user into '&'
>entities, then when it is reconverted, a '<' will be a '<' and a '&lt;'
>will be '&lt;'
>

Received on Friday, 11 February 2000 04:11:30 UTC