Post #2751719
2025-08-17 19:10 UTC
@rumpel@chaos.social the whole point of XSLT is that it allows direct view of the XML in browser, *without* wrapper HTML and *without* JavaScript, which is a *much* higher security risk than XSLT.
If browsers have a security issue in their XSLT implementation, the solution is to fix the implementation, not to remove XSLT.
Replies (1)
-
@rumpel@chaos.social 2025-08-19 19:06
@oblomov@sociale.network now also on HN: https://news.ycombinator.com/item?id=44952185 With some more profound discussion and data points.