Hacker News new | past | comments | ask | show | jobs | submit login

I don't know what you mean by "90% problem", but unlike what your blog article suggests, Django's template engine escapes everything by default. You have to explicitly pass content through a filter to request that it not be escaped.

Based on the fact that the suggestions in your blog article could easily support someone forgetting the "|escape" on a variable, I would accuse your methodology of only solving the "90% problem".

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
