Hi, +1 Good proposal! We don't want all those script kiddies ruining the good name of Sling 2.0.0 Enterprise Edition, S2EE.
On Wed, Apr 1, 2009 at 10:05 AM, Bertrand Delacretaz <[email protected]> wrote: > With one exception, maybe...due to its inherent type safety, and > available enterprise-level tooling, JSP is probably the only scripting > language that deserves to stay. I would suggest that we only allow JSP documents using the XML syntax. Those pesky % characters are evil as noted also by Vidar in a different thread. Also, I propose that we disable the <jsp:scriptlet/> element. All such code should be placed in tag libraries as proper Java classes. BR, Jukka Zitting
