Home. 
.

transparent

transparent

transparent

Altova Mailing List Archives


Re: Questions about character entities in XML and PCI security compliance

From: tempest@----.---
To: NULL
Date: 8/8/2008 3:45:00 PM

On Fri, 8 Aug 2008 07:55:19 +0100, "Joe Fawcett"
<joefawcett@n...> wrote:

>Well we have similar files and I've never seen that happen. As you say they 
>seem to be escaping twice. In my opinion they're wrong but I'd need to know 
>their process etc.
>Pragmatically you may need to un-escape once before treating the file as 
>XML.

I think I will just do what you suggested and write an extra process
to convert ("un-escape") bad character entities to proper entities
first before passing parsing XML files.

At least I am glad that someone agrees with me that the third party
ecommerce site is not exporting proper character entnites in their XML
file.  They refused to fix the problem and used PCI security policy as
their excuse.

I spent several hours on Google tyring to find if there is any
relevancy at all between the use of XML character entities and PCI
security.  And I found none.


transparent
Print
Mail
Digg
delicious
Disclaimer
.

These Archives are provided for informational purposes only and have been generated directly from the Altova mailing list archive system and are comprised of the lists set forth on www.altova.com/list/index.html. Therefore, Altova does not warrant or guarantee the accuracy, reliability, completeness, usefulness, non-infringement of intellectual property rights, or quality of any content on the Altova Mailing List Archive(s), regardless of who originates that content. You expressly understand and agree that you bear all risks associated with using or relying on that content. Altova will not be liable or responsible in any way for any content posted including, but not limited to, any errors or omissions in content, or for any losses or damage of any kind incurred as a result of the use of or reliance on any content. This disclaimer and limitation on liability is in addition to the disclaimers and limitations contained in the Website Terms of Use and elsewhere on the site.

.
.

transparent

transparent