[pLog-svn] r6443 - plog/branches/lifetype-1.2/templates/admin
Jon Daley
plogworld at jon.limedaley.com
Mon May 5 14:47:28 EDT 2008
On Mon, 5 May 2008, reto at devel.lifetype.net wrote:
> guess I was too optimistic with the release. We really should take time
> and rethink our input validation.
Yes, I agree.
One thing I don't like about these fixes in the templates, is why are we
displaying stuff that needs to be escaped at all - if the data is invalid,
why display it at all? Or maybe better said, why is this filtered on the
template level instead of the action or view level?
More information about the pLog-svn
mailing list