They’re special, act like it
• Encode characters using HTML character entity (
<
) or
decimal (
<
) references
• Encode characters in both body copy
and
URLs:
No:
<a href="default.asp?foo=
bob&bar=yes">link</a>
Yes:
<a href="default.asp?foo=
bob&bar=yes">link</a>
Yes:
<a href="default.asp?foo=
bob&bar=yes">link</a>