Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SXML is a fairly old thing, but it isn't really typed. [0]

Rather, things are structured, so it's more like a in-memory representation of XML. It doesn't need to be serialised, only deserialised into XML's text syntax. In which case, each piece knows how it needs to be encoded.

           '(h1 (@ (id "greeting")) "Hi, there")
Its just lists of Symbol types, and string or other type values.

[0] https://en.m.wikipedia.org/wiki/SXML



Understood, but if I insert a string into a database that looks like this:

  <script>alert("yoov bin acked")</script>
And that's my username, if it's naively inserted inside some HTML it'll look like HTML to a browser.

So I was wondering if this framework auto-HTML-escapes strings inserted into places where text can go.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: