http://googleonlinesecurity.blogspot.com/2009/03/reducing-xss-by-way-of-automati
c.html
This protects against the template author making a mistake in specifying
the escaping formatter. Since JSON Template is trivial to tokenize, it
shouldn't be that hard.
Original issue reported on code.google.com by gtempacc...@yahoo.com on 10 Apr 2009 at 7:40
Original issue reported on code.google.com by
gtempacc...@yahoo.com
on 10 Apr 2009 at 7:40