My feeling would be no. I like the way it currently works.

JSStringFormat does what the function says. It is not called JSSafeFromAnything.

As you point out, it is only unsafe under certain conditions. So I am
glad it does not always strip everything out that might possibly meet
a seldom seen condition.



On Dec 31, 2007 4:09 PM, Brad Wood <[EMAIL PROTECTED]> wrote:
> >> I had always believed that jsstringformat did absolutely
> >> everything necessary to string of text in order to set it
> >> into a JavaScript string variable.
>
> > JSStringFormat escapes JavaScript metacharacters; nothing more,
> nothing
> > less. That's all it does, and that's all it's supposed to do.
>
> The LiveDocs for CF7 simply state jsstringformat returns "A string that
> is safe to use with JavaScript.".  I think it is obvious that
> "</script>" is not a "safe" string under certain JavaScript conditions.
>
> Ok, so technically, "</script>" IS safe with JavaScript alone-- but it
> isn't a "safe" string to have in JavaScript which is embedded in an HTML
> document-- and most JavaScript is found in HTML documents.  I don't
> think there's anything particularly wrong with your exacting definition
> of the function-- what I'm asking here is _should_ that be the way the
> function works?
> So it seems jsstringformat may meet the letter of the law.  Everybody
> pat Adobe on the back.  But isn't it a bit misleading?  Could it be
> better?  Should there be a second function which makes a string safe for
> JavaScript embedded in an HTML document?
> Yeah, sure-- there's the replacenocase() function, but again we don't
> really NEED jsstringformat either.  We could replace those
> meta-characters manually as well.  Obviously Adobe doesn't make a
> function for EVERYTHING we need, but what I am trying to do is to get
> people to stop and think if it would be useful to re-define this
> function or add another.  Discussion is what I'm looking for-- not for
> someone to jump down my throat and inform me its working as designed.
>
> I like ColdFusion because it takes those tricky mundane things and makes
> them simpler.  Htmleditformat.  Jsstringformat.  ParagraphFormat.
>
> This seems like one of those places where CF might have missed an
> opportunity.
>
> > What does that have to do with JSStringFormat, or CF at all for that
> > matter? You can do that in an HTML page, without CF at all, and get
> the
> > exact same result, right?
>
> You are absolutely right.  That was a simplified HTML example to show
> the browser behavior.  Had you kept reading, you would have seen the
> example which involved ColdFusion.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Adobe® ColdFusion® 8 software 8 is the most important and dramatic release to 
date
Get the Free Trial
http://ad.doubleclick.net/clk;160198600;22374440;w

Archive: 
http://www.houseoffusion.com/groups/CF-Talk/message.cfm/messageid:295605
Subscription: http://www.houseoffusion.com/groups/CF-Talk/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4

Reply via email to