Allow ..... Tags = disarm

Julian Field mailscanner at
Wed Nov 5 16:00:18 GMT 2003

At 15:40 05/11/2003, you wrote:
>On Wed, 2003-11-05 at 15:07, Furnish, Trever G wrote:
> >What's the point of disarming input tags when form tags are taken out?
> >An input without a form does nothing.
> >Changing the type of buttons seems like a very bad idea to me - I can
> >easily
> >imagine a lot of confusion resulting and it doesn't seem like a useful
> >change.
>I can easily imagine a lot of confusion when users click 'Submit' and
>nothing happens because the form tags disappear.  Are there really
>legitimate reasons for sending forms by email?  (By legitimate I mean
>reasons why people would actually want to recieve a form in an email?)

In which case set it to no instead of disarm.

>Scripts of any kind in email are a bad thing, Its pretty trivial to
>write javascript (or VB script probably) which attaches itself to an
>object (say a button or hyperlink) without including an on.... event in
>the tag.  Ideally we should remove all on..... attributes from all tags
>and disarm all script tags - but maybe this is getting too much?

I don't like dictating how people run their systems. I could write a
general-purpose disarmer as someone suggested, but it would be slow due to
the way HTML::Parser works (it would a function call for all the tags in
all the messages in all the bars in all the world) (Apologies for abusing
Humphrey Bogart :-)

Julian Field
MailScanner thanks transtec Computers for their support

