Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 675297
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 14, 20262026-05-14T00:48:09+00:00 2026-05-14T00:48:09+00:00

In GWT javadoc, we are advised If you only need a simple label (text,

  • 0

In GWT javadoc, we are advised

If you only need a simple label (text,
but not HTML), then the Label widget
is more appropriate, as it disallows
the use of HTML, which can lead to
potential security issues if not used
properly.

I would like to be educated/reminded about the security susceptibilities. It would be nice to list the description of the mechanisms of those risks.

Are the susceptibilities equally potent on GAE vs Amazon vs my home linux server?
Are they equally potent across the browser brands?

Thank you.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-14T00:48:10+00:00Added an answer on May 14, 2026 at 12:48 am

    The security risk of using the HTML widget is that it doesn’t escape html characters like the Label widget does. This opens up the possibility of Cross-site scripting (XSS). Therefore you should not use it to display data supplied from users. There’s risk in itself to use it for string literals in your code.

    How your GWT project is deployed doesn’t matter much for the security risk, as the risk is there anyway if you allow user supplied data being printed back unescaped. But how your site is used, e.g. how much content is user contributed, and how popular your page is have a huge effect of how likely it is that someone actually will exploit a weakness.

    Though … if you have a habit of typing malicious javascript in your own sourcecode using Labels won’t help anyway… 😛

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

GWT Label widgets iterprets everything as text, not as html tags - that's good,
GWT's Editor framework is really handy and it can not only be used for
I am using this api http://gwt-google-apis.googlecode.com/svn/javadoc/maps/1.1/index.html , the GWT Google Maps API, in my
In GWT if I do RootPanel.get(someDiv).add(myPanel); I invariably get: <div id=someDiv><div></div></div> But, I just
I need to get the day, month, year details from a Date value but
GWT RPC is proprietary but looks solid, supported with patterns by Google, and is
Can GWT be used just for simple AJAX? I dont want the widgets, I
GWT Activities/Places/MVP concepts were discussed quite a lot here, but I haven't found a
GWT's serializer has limited java.io.Serializable support, but for security reasons there is a whitelist
I'm new to smart gwt and I need some help. Please help with some

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.