There was bound to be a 2.0.1, it's embarrassing that it's so soon after 2.0
From the changelog: A silly mistake was discovered in dwr.util.containsXssRiskyCharacters()
just hours after the release of version 2.0. This was fixed in version
2.0.1. The original version can not be trusted to perform correct
analysis of XSS risky characters.
http://getahead.org/dwr/changeloghttp://getahead.org/dwr/download
https://dwr.dev.java.net/servlets/ProjectDocumentList?folderID=7355Thanks to Ilya Perminov for pointing the mistake out.
Joe.