On Thu, 2024-04-04 at 17:19 +0000, Dimitre Novatchev
dnovatchev@xxxxxxxxx wrote:
>
> As one small first step, we could add such a timeout to the myriads
> of options that are possible to provide to fn:transform.
I think this should be left as a quality of implementation issue,
although a note suggesting CPU or time limits may be helpful.
On the other foot, the billion laughs attack exists in every language
that can combine strings, but was used to persuade people to move away
from using XML.
liam
--
Liam Quin,B https://www.delightfulcomputing.com/
Available for XML/Document/Information Architecture/XSLT/
XSL/XQuery/Web/Text Processing/A11Y training, work & consulting.
Barefoot Web-slave, antique illustrations: B http://www.fromoldbooks.org
|