[Zope-Coders] Towards 2.6

Brian Lloyd brian@zope.com
Wed, 16 Oct 2002 17:18:18 -0400


> Oh I'm not concerned with me or my clients, I'm concerned about all the
> users wanting to upgrade to 2.6. Localizer still has to monkey patch the
> ZPT StringIO because it won't work for lots of people otherwise. It's a
> pity.
> 
> I don't like the state of all the XSS holes either.

Note that they will not be holes in 2.6 due to the string 
tainting changes being activated by default.


Brian Lloyd        brian@zope.com
V.P. Engineering   540.361.1716              
Zope Corporation   http://www.zope.com