[whatwg] base64 entities

Aryeh Gregor Simetrical+w3c at gmail.com
Thu Aug 26 13:10:49 PDT 2010


On Thu, Aug 26, 2010 at 5:58 AM, Julian Reschke <julian.reschke at gmx.de> wrote:
> Not convinced. There's already one way to escape these things, and this is
> supported in all UAs.

Adam gave two examples of cases where htmlspecialchars() is
insufficient, even if authors do use it.  This proposal is completely
general and will work anywhere, even in <script>.  Is automated
general escaping even possible right now in <script> for text/html?



More information about the whatwg mailing list