|
[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message] Re: Excellent IETF BCP on XML
Simon St.Laurent wrote, > rsalz@d... (Rich Salz) writes: > > No, a namespace URI is an identifier, and therefore need not be > > followed. The document (which is excellent) is talking about, you > > know, external ENTITY things. > > So is RDDL now a security risk? Potentially ... yes. How many times have we discussed the external entity thing on this list now? Any of the issues with them apply equally here. And in fact David Megginson warned about the dangers of automagically dereferencing namespace URIs long before RDDL came along, http://lists.xml.org/archives/xml-dev/200101/msg00057.html Cheers, Miles
|
PURCHASE STYLUS STUDIO ONLINE TODAY!Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced! Download The World's Best XML IDE!Accelerate XML development with our award-winning XML IDE - Download a free trial today! Subscribe in XML format
|
|||||||||

Cart








