This message is in response to the thread at:

http://groups.google.com/group/TiddlyWikiDev/browse_frm/thread/54e526cf8b0f0cc3/4988e4438e7c3a74

but apparently it is too old for me to reply to directly.

I've been considering the issue some more lately, including
information in the thread and recent updates to the trac ticket:
http://trac.tiddlywiki.org/ticket/866

While there are clever solutions which involve managing content from
bags at output time these, to me, are fraught with danger, complexity
and performance issues. It is far more stable, predictable and
performant to sanitize input when we get it and store the sanitized
data in the datastore.

One way to do this (as mentioned before) would be to add another field
to Policy objects which states that writes to this bag (or perhaps
recipe) must be sanitized. The tiddler.text is then passed through a
sanitation routine, based on similar code out there in the world,
modified for tiddlywiki-ness.

Presumably one could make the sanitation routine pluggable.

Does this seem workable to people?

Any other suggestions?
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"TiddlyWikiDev" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/TiddlyWikiDev?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to