Hi,

in the method org.apache.myfaces.shared.renderkit.html.util.HTMLEncoder.encode there is not implemented conversion of control characters into HTML entities, eg. 0x1E (Record Separator) on &#x1e, is it for some reason? According XML 1.0 spec and HTML spec there are not allowed control chars except 0x09, 0x0A, 0x0D. The rest of them should not appear in an HTML document.

According my opinion those, that are not converted, should be ignored in HTMLEncoder.

Regards,
Stan

--
Ing. Stanislav Pacvoň
analytik-programátor

AURA, s.r.o.
Úvoz 499/56
602 00 Brno
Česká republika

Tel.: +420 544 508 151
Fax: +420 544 508 112
E-mail: [email protected]
Web: http://www.aura.cz

Certifikace ISO 9001, ISO 8000, ISO 27001 a ČOS 051622 (AQAP 2110)

Reply via email to