Simon Willison’s Weblog

Blogmarks tagged xss, security, autoescaping, django in Nov

Filters: Type: blogmark × Month: Nov × xss × security × autoescaping × django ×


Django Changeset 6671. Malcolm Tredinnick: “Implemented auto-escaping of variable output in templates”. Fantastic—Django now has protection against accidental XSS holes, turned on by default. # 14th November 2007, 5:05 pm