[whatwg] Parsing: < in unquoted attribute values

Anne van Kesteren annevk at opera.com
Wed Apr 25 23:59:58 PDT 2007


On Thu, 26 Apr 2007 02:17:12 +0200, Jonas Sicking <jonas at sicking.cc> wrote:
> We do no longer support this in mozilla (if we ever did). A reason we  
> now explicitly forbid this is we don't want it to ever be possible to  
> create elements with 'illegal' names. Same thing goes for attribute  
> names. This is partially for security reasons since some elements and  
> attributes carry very important security information.

Could you elaborate on the security issues? Could you also give a  
definition of "illegal names" as it's not really clear to me what that  
means for HTML.


> I fully agree with Simons original proposal though.


-- 
Anne van Kesteren
<http://annevankesteren.nl/>
<http://www.opera.com/>



More information about the whatwg mailing list