Check out:
http://www.ietf.org/rfc/rfc1738.txt
Search for "unsafe" in that. You'll learn that braces are considered unsafe and should be escaped. Just because your browser lets you get away with this doesn't mean that it's safe to use. So, yes, it's not server side mistake, it's client side mistake.
↧