|
|
|
|
|
by lolinder
525 days ago
|
|
The concern isn't that it was JS, the concern is that there's a scripting system inside of PDF at all. Why? What? Form validation is a lousy excuse because forms themselves were a bridge too far for the format. Why do we need to be able to validate them? I knew PDFs could be dangerous, but I didn't realize it was because they're intentionally designed to allow embedded scripts. |
|
However, forms could be handled by a very simple DSL that would be easy to write a safe interpreter for.