4 ms·
> But it is not a good idea to use input sanitization as the only (or even main) method of injection attacks prevention Can you define what you mean by "input
by yetanotherjosh 9y ago
> But it is not a good idea to use input sanitization as the only (or even main) method of injection attacks prevention
Can you define what you mean by "input sanitization"? Because in my mind, a prepared statement is doing just that. You say what part is your SQL, what part is your user input, and you let the DB adapter sanitize the input to build the final statement. You aren't writing sanitization code yourself, you're leaving it up to a library, but that's still what's happening. Or do you have a different term for what's going when a prepared statement routine converts user input into SQL-safe strings?