3 ms·
It's actually quite easy: 1. Sanitize input when you actually need/want to do that but at least to a degree that it's save to put in a database (e.g. through p
by rawfan 7y ago
It's actually quite easy:
1. Sanitize input when you actually need/want to do that but at least to a degree that it's save to put in a database (e.g. through prepared statements)
2. Always validate input
3. Always escape output (unless you have a reason not to).