Hacker News new | past | comments | ask | show | jobs | submit login

It's really not that difficult if you use a parser + whitelist. You don't have to care about this sort of thing if you limit people to using certain tags/attributes in WYSIWYG editors and other inputs.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: