[Cubicweb] annotating divs with rql and vid

Sylvain Thénault sylvain.thenault at logilab.fr
Fri May 25 08:48:53 CEST 2012


On 24 mai 23:27, Adrien Di Mascio wrote:
> On Thu, May 24, 2012 at 9:39 PM, Sylvain Thénault
> > Corrolary points:
> >
> > * what can't we have by disabling rql input, beside allowing user to type
> >  arbitrary rql?
> 
> There are quite a few places in CW or cubes where urls with explicit
> rql and vid parameters are generated. If you disable the rql parameter
> (which is not that hard), you'll get bitten there.

yes, though IMO most of those could be avoided. And that's precisely the
work to be done so one can disable rql input: I would want the default ui
(and core cubes) still working.

-- 
Sylvain Thénault, LOGILAB, Paris (01.45.32.03.12) - Toulouse (09.54.03.55.76)
Formations Python, Debian, Méth. Agiles: http://www.logilab.fr/formations
Développement logiciel sur mesure:       http://www.logilab.fr/services
CubicWeb, the semantic web framework:    http://www.cubicweb.org


More information about the Cubicweb mailing list