April 1, 2009
3:41 am

Google security team has introduced Automatic Context-Aware Escaping (Auto-Escape for short), a functionality added to two Google-developed general purpose template systems to better protect against Cross-Site Scripting (XSS). Consider the simplified template below in which double curly brackets {{ and }} enclose placeholders (variables) that are replaced with run-time content, presumed unsafe. In this template, four variables are used: USER_NAME, USER_ACCOUNT_URL, USER_COLOR, USER_ID

Full Article

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« Spam in Q1 2009 increased 1.2% per dayYahoo! Mobile launches with 300-plus devices around the world »
Feed Icon

Subscribe via RSS or email: