In skimming the new code from the last two weeks, I've come across things like this:
$('#foo').html('<?php echo T('Foo') ?>');
$('#foo').html('<?php echo JS(T('Foo')) ?>');
I've added comments about this to the development wiki.
If you've been guilty of this sort of escaping sin, please fix it up.
Hmmn. The bottom of that message seems messed up. Here's what it should have looked like:
I am sure I am the source of most of what you are pointing out. I see what you are trying to do, but honestly don't see the problems you are trying to avoid. I haven't noticed any translation oddities and 'XSS vulnerability' is over my head completely.
In my own world, all this code is used inside a controlled environment - local LAN - so haven't been very concerned about external security. Perhaps that's blissful ignorance, plain good luck, or something.
An English-speaking home user will never run into either of these problems.
The first problem will cause frustration for translators down the road. Imagine that the proper translation of 'Foo' in some language includes an apostrophe - say it's "B'ar". Then the JS code from OpenBiblio becomes:
Good points, and never occurred to me at all. Guess I'll have to find a way to get your JS() function into my stuff.
Incidently the current split still useful in your opinion? I'm not sure its gaining anything unless you want to protect your work. Trying to take advantage of what you are doing seems awkward at best.
There are two kinds of split I know of, and I think they have both outlived their usefulness. The first is the difference between mstetson/obiblio-10-wip and flaplante/obiblio-10-wip. You and Luuk are doing most of the work right now, and it's silly not to just let you commit to my repo. I've just given both of you permission to do so; you can push directly there if you like. The other split is between the "your" code and "my" code. We want one body of OpenBiblio code. So when you change or improve something, do it boldly. Do what you think is right, and don't worry about leaving certain files or lines alone. If I don't like what you're doing, I'll tell you, and hg gives us an undo button.
OK, I think you are correct. Time to remerge these things. Do you want to pull the current stuff from my change set into yours. and then I will abandon mine completely. If Luuk want to keep it for his multi-site work thats fine with me.
Let me know when it is OK to start commiting to your repository.