On Mon, 5 Apr 2004 16:48:20 +0200
"Henner Kollmann" <[EMAIL PROTECTED]> wrote:

HK> Let's make a list:
HK> 
HK>     tag/attribute                   minimum escape chars
HK> ===============================================================
HK>     each value attribute            " '     
CARRIAGE RETURN and LINE FEED probably must be encoded in the attributes
too. For safety maybe is best to encode all chars < 32. 

HK>     plain text                      < >

Thinking about this, probably we must provide 3 levels of encoding for
plain text data place on the HTML :
1. default encode all HTML entities
2. encode only <> (field data does not interfere in HTML page)
3. encode nothing, this make possible to have the HTML fragments in
fields.


-- 


Ivan F. Martinez


-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
DbForms Mailing List

http://www.wap-force.net/dbforms

Reply via email to