4 ms·
If you're preventing SQL injection, you do need to run the variable through a filter (mysql_real_escape_string, parameter binding, etc.) in order to prevent a s
by onteria 16y ago
If you're preventing SQL injection, you do need to run the variable through a filter (mysql_real_escape_string, parameter binding, etc.) in order to prevent a successful attack.
The other issue is that if I encode entities when inserting html, that means I have to call this on every page view. For simple strings that's not too big a deal, but if I have a lot of content, this gets resource intensive pretty fast for larger scale sites with lots of people hitting a page at once.
In this case I'd rather due the encoding once, which handles a majority of cases.
- prodigal_erik 16y agoEncoding is dirt cheap. You probably pay more just for a TCP stack that isn't perfectly tuned for your workload. And you can't pre-encode a string without baking in bad assumptions that you know how it may ever be used. You're going to regret having your data store polluted with HTML-specific encoding as soon as you build an API or integrate a third-party tool (e.g., analytics or sales support), because they will need either raw values or some different encoding than HTML text (SGML entities).