view tests/headers.ur @ 1710:540df112ff62

Remove string-valued style attribute, which may allow injection attacks
author Adam Chlipala <adam@chlipala.net>
date Sun, 15 Apr 2012 12:40:53 -0400
parents 2f5fd248588d
children
line wrap: on
line source
fun action () =
  setHeader (blessResponseHeader "Location") "http://www.google.com/";
  return <xml/>

fun main () =
  ag <- getHeader (blessRequestHeader "User-Agent");
  return <xml><body>
    User agent: {[ag]}

    <form> <submit action={action}/> </form>
  </body></xml>