Simon Willison’s Weblog

Items tagged django, autoescaping, malcolmtredinnick, xss, security

Filters: django × autoescaping × malcolmtredinnick × xss × security ×


Django Changeset 6671. Malcolm Tredinnick: “Implemented auto-escaping of variable output in templates”. Fantastic—Django now has protection against accidental XSS holes, turned on by default. # 14th November 2007, 5:05 pm