[cap-talk] solve CSRF by making references unforgeable, not unshareable

Mark Miller erights at gmail.com
Thu Mar 26 20:10:14 EDT 2009

On Wed, Mar 25, 2009 at 10:49 AM, Kevin Reid <kpreid at mac.com> wrote:
> Indeed. My E-on-JavaScript implementation suffers from the lack of AST
> libraries for HTML and JavaScript (though I built a half-baked output-
> only system for JS).
> Are there existing ones that it would be good to borrow design or tame
> implementation of? (DOM need not apply as it uses mutable nodes tied
> to a specific Document.)

For HTML / XML / DOM, see http://jsonml.org/

Text by me above is hereby placed in the public domain


More information about the cap-talk mailing list