Re: A web page security enhancement demo patch

2009-02-06 Thread Byron Foster
On Feb 5, 2009, at 21:45 , Leon sdh5724 wrote: Dear Devs, Velocity is a great opensource component for weg page render. We deploy it on our site that render dynamic web pages more than 1 billion pages everyday. Wow, 1 Billion... That's traffic. But velocity have no security

Re: A web page security enhancement demo patch

2009-02-06 Thread Leon sdh5724
2009/2/6 Byron Foster by...@base2.cc On Feb 5, 2009, at 21:45 , Leon sdh5724 wrote: Dear Devs, Velocity is a great opensource component for weg page render. We deploy it on our site that render dynamic web pages more than 1 billion pages everyday. Wow, 1 Billion... That's

A web page security enhancement demo patch

2009-02-05 Thread Leon sdh5724
Dear Devs, Velocity is a great opensource component for weg page render. We deploy it on our site that render dynamic web pages more than 1 billion pages everyday. But velocity have no security protected xss + csrf attack. Every render reference point need programmer writing code as