Re: [whatwg] More prohibited characters for unquoted attributes are needed

2009-10-13 Thread Geoffrey Sneddon
Ian Hickson wrote: On Mon, 7 Sep 2009, Aryeh Gregor wrote: On Mon, Sep 7, 2009 at 1:34 PM, Geoffrey Sneddon foolistbar at googlemail.com wrote: Apparently Hixie had previously said he didn't want to change this as it will become a non-issue over time. I think it does matter due to the security

Re: [whatwg] More prohibited characters for unquoted attributes are needed

2009-10-04 Thread Ian Hickson
On Mon, 7 Sep 2009, Aryeh Gregor wrote: On Mon, Sep 7, 2009 at 1:34 PM, Geoffrey Sneddon foolist...@googlemail.com wrote: Apparently Hixie had previously said he didn't want to change this as it will become a non-issue over time. I think it does matter due to the security issues it

Re: [whatwg] More prohibited characters for unquoted attributes are needed

2009-09-14 Thread Ian Hickson
On Sun, 6 Sep 2009, Aryeh Gregor wrote: See some research here: http://code.google.com/p/html5lib/issues/detail?id=93 It seems like in addition to whitespace and '= , the characters U+ through U+0020 should be banned from unquoted attribute values, as well as U+0060 (backtick `),

Re: [whatwg] More prohibited characters for unquoted attributes are needed

2009-09-07 Thread Aryeh Gregor
On Mon, Sep 7, 2009 at 1:34 PM, Geoffrey Sneddon foolist...@googlemail.com wrote: Apparently Hixie had previously said he didn't want to change this as it will become a non-issue over time. I think it does matter due to the security issues it presents in existing UAs. Conforming markup (using

Re: [whatwg] More prohibited characters for unquoted attributes are needed

2009-09-07 Thread Geoffrey Sneddon
On 6 Sep 2009, at 12:35, Aryeh Gregor wrote: See some research here: http://code.google.com/p/html5lib/issues/detail?id=93 It seems like in addition to whitespace and '= , the characters U+ through U+0020 should be banned from unquoted attribute values, as well as U+0060 (backtick `),