Non-namespace aware Yadis file parsing

Martin Atkins mart at degeneration.co.uk
Sat May 20 11:01:09 UTC 2006


Johannes Ernst wrote:
> Dan raised the issue of namespaces in the Yadis file. I've been  giving 
> it some thought, in particular whether we require implementors  to truly 
> process them all under all circumstances, or we think people  might get 
> aware of namespace-unaware XML parsing, or even regexes.
> 
> It appears to me that if we don't require full XML parsing on the  other 
> end,
>  - there may be security problems (relying parties may mis-interpret  
> the content of a Yadis file)
>  - there may be interoperability problems (because it's hard to test  
> against a spec -- for "restricted namespaces a la Yadis conventions"  -- 
> that doesn't exist)
>  - there may be substantial extensibility problems (e.g. can't  insert 
> CDATA into Yadis files, may conflict with other namespaces in  the 
> future etc.)
> 
> So the conclusion I have come to so far is that we got to require  full 
> namespace support.
> 
> Does anybody agree or disagree with that?
> 

Sounds fair to me.

XML parsing with namespaces isn't *that* hard. There are dozens of 
libraries that'll do all the work for you!



More information about the yadis mailing list