On Jun 9, 2017, at 12:17 PM, Ross Berteig <r...@cheshireeng.com> wrote:
> 
> I do think that the JSON support is close to solid enough to be on by default.

For functionality alone, that is surely true, but in the face of malice?  
Parsers are notoriously difficult to make bomb-proof.

Even if the JSON API is 100% solid, it acts as an API to the rest of Fossil.  
Some fuzzing the JSON API might find a way to break Fossil itself, a good thing 
if we do it before the black hats do.

_______________________________________________
fossil-users mailing list
fossil-users@lists.fossil-scm.org
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

Reply via email to