[whatwg] Parsing: < in unquoted attribute values
Anne van Kesteren
annevk at opera.com
Wed Apr 25 23:59:58 PDT 2007
On Thu, 26 Apr 2007 02:17:12 +0200, Jonas Sicking <jonas at sicking.cc> wrote:
> We do no longer support this in mozilla (if we ever did). A reason we
> now explicitly forbid this is we don't want it to ever be possible to
> create elements with 'illegal' names. Same thing goes for attribute
> names. This is partially for security reasons since some elements and
> attributes carry very important security information.
Could you elaborate on the security issues? Could you also give a
definition of "illegal names" as it's not really clear to me what that
means for HTML.
> I fully agree with Simons original proposal though.
--
Anne van Kesteren
<http://annevankesteren.nl/>
<http://www.opera.com/>
More information about the whatwg
mailing list