[Home] [By Thread] [By Date] [Recent Entries]


Simon St.Laurent wrote,
> rsalz@d... (Rich Salz) writes:
> > No, a namespace URI is an identifier, and therefore need not be
> > followed. The document (which is excellent) is talking about, you
> > know, external ENTITY things.
>
> So is RDDL now a security risk?

Potentially ... yes.

How many times have we discussed the external entity thing on this list 
now? Any of the issues with them apply equally here.

And in fact David Megginson warned about the dangers of automagically 
dereferencing namespace URIs long before RDDL came along,

  http://lists.xml.org/archives/xml-dev/200101/msg00057.html

Cheers,


Miles

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member