Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's also a security reason for attributes to be enclosed in quotes when we're talking about dynamic webpages. Avery's permissive parser might parse the page "correctly," including an additional maliciously injected attribute like onclick=sendcookie(), which wouldn't have been possible otherwise.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: