In message <mailman.674.1159276196.10491.python-list at python.org>, Fredrik Lundh wrote: > most HTML attributes cannot even contain things that would need > to be escaped ... sys.stdout.write \ ( "Email: <INPUT TYPE=\"TEXT\" NAME=\"email_address\" VALUE=\"%s\">\n" % QuoteHTML(WhateverTheUserPreviouslyTyped) )