[Esa-l] Re: FYI regarding the Anomy sanitizer

John D. Hardin jhardin at wolfenet.com
Sat Feb 3 09:31:03 PST 2001

On Fri, 2 Feb 2001, Bjarni R. Einarsson wrote:

> > I've added LAYER to the development version - was ILAYER in the
> > announcement as well?
> I don't even know if ILAYER exists.  I was doing the work offline,
> and figured "better safe than sorry".

I was reading through the advisories again, and all of the examples I
found were based on the DIV tag with a "z-index:0" argument.
Fortunately the current sanitization seems to deal with it:

  <div id="layer4" DEFANGED_STYLE="width:99px; height:99px;
   position:absolute; left:0px; top:0px; z-index:0;">

(Assuming, of course, you aren't trusting STYLE tags on inbound

