On Thu, Dec 30, 2010 at 9:16 PM, Marius Gedminas <mar...@gedmin.as> wrote:
(...)
>
> That's a bit ironic: I spent about an hour writing tests for
> html_escape, without noticing your email, resulting in duplicated
> effort.
>

I'm sorry about that. I just point out my old fork to help. Not to
make the work of others contributors painfull.

> See
>
>  https://bitbucket.org/mgedmin/webob/changeset/367603e5138b
>
> compare with
>
>  https://bitbucket.org/mgedmin/webob/changeset/ed29414cd65b#chg-tests/html_escape.txt
>
> I like mine maybe a bit better -- it has descriptions, and, I think,
> tests a few more cases.  *shrug*
>
> My repository currently has two unmerged heads, and I'm uncertain what
> to do about it.
>

Just to let you know that I have no problem if my patch is removed.

--
Gael

>
> Incidentally, one thing I noticed during this exercise was that
> WebOb.html_escape("'") doesn't escape the '.  This can be considered a
> security issue, see http://www.cvedetails.com/cve/CVE-2010-2480/
>
> Marius Gedminas
> --
> Similarly, many of us don't care for slacker email correspondence where all 
> the
> words are in lower case. Frankly, if you're going to bother to write to me, 
> the
> least you can do is use your shift key to capitalise letters now and again YOU
> BORDERLINE ILLITERATE SLOB.
>        -- Stuart Jeffries
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.10 (GNU/Linux)
>
> iEYEARECAAYFAk0c6JQACgkQkVdEXeem148NvACfVK8P9CmqqN7wjeb39YB6m0P1
> 1IEAoJN679s9L73QPacetp31SleUBToN
> =tkId
> -----END PGP SIGNATURE-----
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"pylons-devel" group.
To post to this group, send email to pylons-de...@googlegroups.com.
To unsubscribe from this group, send email to 
pylons-devel+unsubscr...@googlegroups.com.
For more options, visit this group at 
http://groups.google.com/group/pylons-devel?hl=en.

Reply via email to