[Standards] XEP-0390: use of separators which are valid (but discouraged) in XML 1.1 (as opposed to 1.0)

Kevin Smith kevin.smith at isode.com
Mon Mar 5 09:46:33 UTC 2018

On 5 Mar 2018, at 09:33, Florian Schmaus <flo at geekplace.eu> wrote:
> On 05.03.2018 09:04, Jonas Wielicki wrote:
>> Dear list,
>> Florian discovered that the ASCII separators we use, while invalid in XML 1.0 
>> (upon which RFC 6120 bases), are only discouraged in XML 1.1. 
>> I wonder whether we should be concerned about this. 
> I wouldn't be worried, as I'd expect XMPP to stay XML 1.0 for a
> foreseeable future. If you violate XML 1.0 and accept non well-formed
> XML 1.0, then it is not really something extension protocols have to
> consider.

I’m not convinced I agree with this. If using an XML 1.1 parser would introduce some security hole in a spec it’s definitely something that needs consideration.


More information about the Standards mailing list