[Home] [By Thread] [By Date] [Recent Entries]
> > 3. Make the schemalocation hint manditory to provide, and manditory to > > dereference for Schema-Loading, WRT XPointer. > > This option really scares me! Me too, but for security reasons. Mandatory to deref means that I as the client can force a server to go open a file of my choosing. That's scary. Suppose I send the server schemaLocation="file:///etc/passwd" -- I could probably guess some account names from the helpful fault information that comes back. /r$
|

Cart



