From: Michael \(michka\) Kaplan (michka@trigeminal.com)
Date: Sun Mar 02 2003 - 12:57:22 EST
From: "Mark Davis" <mark.davis@jtcsv.com>
> I agree with Kent that it is somewhat less robust to simply remove
> ill-formed sequences, since it removes any indication that the data
was
> corrupted.
Nice that the API gives one the option to choose, huh? ;-)
The notion of continuing (even if one is limping along, removing
invalid sequences) is to help some of the backcompat story, where
there were no errors previously -- without adding security errors due
to non-shortest form strings.
> But the final decision should be made by the user of the API, since
the
> desired behavior may vary depending on the environment.
Also agreed.
MichKa
This archive was generated by hypermail 2.1.5 : Sun Mar 02 2003 - 13:31:03 EST