[lxml-dev] Preventing XPath injection

Geoffrey Sneddon foolistbar at googlemail.com
Sun Sep 7 17:53:33 CEST 2008


On 6 Sep 2008, at 18:52, Alex Klizhentas wrote:

> That's strange, I thought it should be quoted like: '

Nope. A string is "[^"]*" or '[^']*' — it is exactly what is between  
the quotes.


--
Geoffrey Sneddon
<http://gsnedders.com/>



More information about the lxml-dev mailing list