4 ms·
Maybe I was not able to make it clear - what I meant was "if you can inject arbitrary code in disabled fields and the system is using those JSON data elsewhere,
by introvertmac 6y ago
Maybe I was not able to make it clear - what I meant was "if you can inject arbitrary code in disabled fields and the system is using those JSON data elsewhere, it can lead to injection attacks"
The whole idea is validate the user inputs - be it disabled fields or normal inputs
- wruza 6y agoIt is more “sanitize” than “validate” then. Saying that you need to sanitize disabled or normal fields in “crypto websites” is like saying that you need to put handrails on 7th floor of a red building to prevent falling down. But in reality you may fall from any height that has no handrails, and 7th floor and a red decoration aren’t specific requirements for falling. I’m not trying to nitpick here, my confusion was genuine. These sorts of statements are hugely misleading even for seasoned folks (“what if I missed something in disabled inputs? why crypto suffers from that?”), and in novice developers it creates magic recipe thinking instead of generic awareness that you never want to execute(user_input).
- introvertmac 6y agoYou made a good point but accepting JS in a currency field requires validation + sanitization. Validate for functional errors then sanitize for injection issues. Hope it makes more sense now! Sorry for any confusion from previous comments or post