<?xml version="1.0" encoding="windows-1252"?>
<node id="842129" title="Re: RFC:Tutorial: Using jQuery, Json, and Perl for Web development" created="2010-05-29 00:22:09" updated="2010-05-29 00:22:09">
<type id="11">
note</type>
<author id="22308">
dws</author>
<data>
<field name="doctext">
Great end-to-end example, with at least problem. In &lt;code&gt;record&lt;/code&gt;, you are escaping the values in the query that you're constructing, but not the keys. That opens the door to an injection attack.
</field>
<field name="root_node">
842126</field>
<field name="parent_node">
842126</field>
</data>
</node>
