TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The Blessing of the Strings

31 pointsby lumpaabout 1 year ago

3 comments

mrkeenabout 1 year ago
&gt; You can think of TrustedHTML as an interface indicating that a string has been somehow specially &quot;blessed&quot; as safe... Sanitized.<p>Unfortunate naming. &quot;Trusted&quot; is one of those words which has taken on its own opposite as a meaning. Like &quot;redundant&quot; or &quot;cope&quot;.<p>This feature would be Checked&#x2F;Validated&#x2F;Trustworthy&#x2F;Safe. Values would end up in this state if you did not trust them and needed to check them.
评论 #39963071 未加载
评论 #39964450 未加载
评论 #39966047 未加载
评论 #39964364 未加载
wavemodeabout 1 year ago
I&#x27;m not quite sure I follow the theat model here?<p>&gt; But wait... can&#x27;t someone come along then and just create a more lenient policy called default? No! That will throw an exception!<p>Who is &quot;someone&quot; in this situation? And why are they able to execute arbitrary JavaScript code in the user&#x27;s browser, yet the user is somehow protected by a string sanitization policy?
评论 #39966778 未加载
评论 #39964836 未加载
评论 #39966786 未加载
oasisaimlesslyabout 1 year ago
TL;DR: Perl&#x27;s taint mode is coming to JavaScript.
评论 #39967380 未加载
评论 #39966868 未加载