In the below message to the WHATWG, Ian suggests that vendors experiment with an API that makes it easier for web developers to programmatically add static HTML content to their pages without XSSing themselves:
http://lists.whatwg.org/htdig.cgi/whatwg-whatwg.org/2009-June/020191.html I think we should do as he recommends. If no one objects, I'll add this to my list of things to work on. Adam _______________________________________________ webkit-dev mailing list webkit-dev@lists.webkit.org http://lists.webkit.org/mailman/listinfo.cgi/webkit-dev