Google Glass Developer program - DOS and XSS

There were two very simple Google Glass Mirror's quickstart DOS and XSS vulnerabilities.  The fixes have been introduced in changeset

The DOS fix is rather simple.  Limit the request to 1000 lines.  The XSS fix is hackish but works.  Instead of reflecting the client's input back to the user, the error is directed to the error logging infrastructure.  Let's hope the error logging infrastructure is anti-XSS enabled.