Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's certainly an improvement over people trying to homebrew their own sanitisers. But that distinction of being XSS-safe is a potentially subtle one, and could end up being dangerous if people don't carefully consider whether XSS-safe is good enough when they're handling arbitrary users input like that.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: