Open GoogleCodeExporter opened 8 years ago
i think -- good (safety) solution will be: BY DEFAULT <%=data %> means
need_to_html_escape_mode
...and special mark for NON_NEED_to_html_escape_mode
Original comment by polymor...@gmail.com
on 25 Jul 2011 at 1:31
Original issue reported on code.google.com by
assortme...@gmail.com
on 7 Nov 2010 at 3:36