http://qs1969.pair.com?node_id=680762


in reply to Re: default_escape for Template::Toolkit?
in thread default_escape for Template::Toolkit?

what do you do to prevent XSS reliably?
The OWASP Guide to Building Secure Web Applications version 3 draft is out. Is is certainly an interesting read for those concerned about web application security.
--
When you earnestly believe you can compensate for a lack of skill by doubling your efforts, there's no end to what you can't do. [1]

Replies are listed 'Best First'.
Re^3: default_escape for Template::Toolkit?
by moritz (Cardinal) on Apr 16, 2008 at 10:53 UTC
    I think the question was directed at TT users. At least mine was.
    Flip HTML::Mason's default_escape_flags

    That's the point. TT doesn't seem to have such a flag (or at least nobody knows about it). HTML::Template and HTML::Mason (documented in HTML::Mason::Compiler have some default escaping mechanism. So what do the TT users do?

    I can't believe they never forget to escape something and therefore don't need a better solution.

      I agree that I have taken tinita's last question in Re: default_escape for Template::Toolkit? out of the original context.

      So what do the TT users do?
      I have no idea. Except consider how important such a feature is, and given it's important, switch to a templating system that supports it.
      --
      When you earnestly believe you can compensate for a lack of skill by doubling your efforts, there's no end to what you can't do. [1]