On Thu, Sep 11, 2008 at 08:54:15AM +0200, Frederik Ramm wrote: > Subject: Re: [OSM-dev] Invalid XML? > > Hi, > > Florian Lohoff wrote: > >Its not that the xml is broken afterwards but people could start putting > >bad things into the database by closing a tag and reopening a new one. > > Excuse me? How do you think that could happen? > > The backslash has no special meaning in XML, it is just a character like > any other. It does not require escaping.
I stand corrected - you are right - at least the main api escapes ">< so one can not inject tags into tag names or values. I need to think about other ways *evil grin* Flo -- Florian Lohoff [EMAIL PROTECTED] +49-171-2280134 Those who would give up a little freedom to get a little security shall soon have neither - Benjamin Franklin
signature.asc
Description: Digital signature
_______________________________________________ dev mailing list dev@openstreetmap.org http://lists.openstreetmap.org/listinfo/dev