[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Security: Atom injection attacks




At 5:40 PM +0100 3/12/07, A. Pagaltzis wrote:
* Sylvain Hellegouarch <sh@xxxxxxxxxx> [2007-03-12 15:30]:
 SHOULD ought to be used almost as carefully as MUST.

More carefully, actually. It introduces a constraint, but does
not guarantee it. Every SHOULD in a spec increases the cost of
implementation. Further, with enough sufficiently widely deployed
implementations, SHOULDs end up either mandatory or ignored.

Further, if we use a SHOULD in the document, we are supposed to give the times it is not a MUST. In this case, that is ridiculous. Therefore, SHOULD/MUST is not called for; advice to the reader is.