|
|
|
|
|
by kijin
13 days ago
|
|
That assumes that you don't have anything else to escape or sanitize. I see people stuffing all sorts of HTML tags and nonstandard attributes in an RSS <description>, just because CDATA allows them to do so without breaking the parser. Images, videos, inline SVGs with maybe some scripts inside... The RSS spec should never have allowed this. Reading a feed would have been much more pleasant (not to mention safer for everyone!) if the contents were required to be in plain text. |
|
At least with a cdata tag your being explicitly told “here be dragons”