4 ms·
Sorry, this still seems like a terribly hacky way to think about code. Again, if you write a template engine or a SQL engine, the code the library's developer
by throwawayjava 7y ago
Sorry, this still seems like a terribly hacky way to think about code.
Again, if you write a template engine or a SQL engine, the code the library's developer writes to determine how holes are safely filled is literally sanitizing input! You never get away from sanitizing inputs, you just do it further from the source and closer to the sink.
> So sanitization of input is a good idea
Right. "Don’t try to sanitize input" is bad advice. Also, the whole point of escaping outputs is that you don't trust inputs. Escaping outputs is done to sanitize inputs.
If by "sanitize input" you mean "add some backslashes to $_GET values like it's 1995", well, I guess, point taken. But then, the actually good advice should be "step back learn how to think more systematically about your code", not "escape outputs instead of inputs!"