Html escaping for security: howto in D?

Fitz fitz at figmentengine.com
Wed Jul 8 17:27:25 UTC 2020


On Tuesday, 7 July 2020 at 18:30:38 UTC, bauss wrote:
> On Tuesday, 7 July 2020 at 17:59:21 UTC, Fitz wrote:
>> On Monday, 6 July 2020 at 15:13:30 UTC, aberba wrote:

> There is no reason to escape / and it might break some parsers 
> for links etc. You should only escape <, >, &, " and '

'/' is in on the OSWASP list. you can use it to break out of a 
html tag.
tbh I can't think about how it can be used?


More information about the Digitalmars-d mailing list