Hi.

> I'm reading about Xajax for the first time but I am already ready to
> back David up on this - it looks horrid. The first thing that amazed me
> is their security model. There doesn't seem to be any. There's no common
> way of validating and normalizing [1] the input, it just goes directly
> to "application logic". Also, direct usage of $_GET (somewhere under the
> hood), obtrusive usage "onclick" and friends... uhhuh. It promises to
> "get the job done fast" but you'll end up with insecure, incoherent
> piece of maintenance nightmare spaghetti.

So I think you're all right, because of we're starting from scratch
we'll try MooTools.

Thanks for your help.

Kind regards,
  Marius.


_______________________________________________
users mailing list
[email protected]
http://lists.agavi.org/mailman/listinfo/users

Reply via email to