option to turn ESCAPE=HTML on by default

Mark Stosberg <mark-WmyhgDpj2fCHT8/[email protected]>
Newsgroups gmane.comp.lang.perl.modules.html-template
Message-ID <[email protected]>
Hello,

I'm curious about what other people think about an option to
turn ESCAPE=HTML on default, to protect against cross script scripting
practices by default. 

This seems especially valuable when the convenient "associate => $q"
option is used. 

Then programmers would be forcing themselves to consciously add
"NOESCAPE=html" to a tag.

To me, this seems like the equivalent of turning "use strict" on by
default, and explicitly declaring "no strict" where needed. 

Thoughts? 

    Mark



-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.