Re: HTML Security Issue

On Fri, 11 Feb 2000, Jeff Sinclair wrote:

> Hi Edward,
> 
> Nice Idea but what if the user put's in "&amp" 
> you can't tell the difference between that and what came 
> out of the database. So if you convert it when going into the
> database you get "&amp" and then "&amp" etc 

Um, isn't the the behaviour you want?  Just keep tabs on whether it is
encoded or not.  It's kinda like dealing with URIs.

-- 
Russell O'Connor                           roconnor@uwaterloo.ca
       <http://www.undergrad.math.uwaterloo.ca/~roconnor/>
``Paradoxically, a refusal to `put a monetary value on life' means that
life is often undervalued.'' -- Artificial Intelligence: A Modern Approach

Received on Friday, 11 February 2000 10:54:46 UTC