Reducing XSS by way of Automatic Context-Aware Escaping in Template Systems

<<Building on our earlier posts on defenses against web application flaws [ “Automating Web Application Security Testing” , “Meet ratproxy, our passive web security assessment tool” ], we introduce Automatic Context-Aware Escaping (Auto-Escape for short), a functionality we added to two Google-de…>>   (more…)

See original post by Chris Gilmer