Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Actually, you should also always indicate the character encoding, for reasons I explain here:

http://shiflett.org/blog/2005/dec/google-xss-example



Yes, declaration is necessary, but not in the htmlspecialchars() call if you're using ASCII-superset encoding (and you really should declare UTF-8, never UTF-7).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: