[Zope] Zope inserting base tag

Jamie Heilman jamie@audible.transient.net
Thu, 27 Feb 2003 12:28:26 -0800


Jaroslav Lukesh wrote:
> OK, this kind of questions are here every month. Use mixed HTML/DTML
> construction:
> 
> <base href="<dtml-var URL1>">

No.  You mean <base href="&dtml-URL1;">.  Never place
client-controlled data into a document without the proper contextual
escaping.

-- 
Jamie Heilman                   http://audible.transient.net/~jamie/
"It's almost impossible to overestimate the unimportance of most things."
							-John Logue