4 ms·
Yes, exactly, the meaning of 'safe string' depends on its context. I personally believe that all code that is sensitive to escaping issues, should be escaped o
by al_james 15y ago
Yes, exactly, the meaning of 'safe string' depends on its context.
I personally believe that all code that is sensitive to escaping issues, should be escaped on output (or storage / sending to the database / whatever) by default unless you explicitly opt it out.
In our framework, we maintain 'already escaped' strings as a separate class, forcing the developer to acknowledge this fact. The HTML output layer escapes all strings unless they are instances of this safe class. Similarly for the SQL layer, all code gets quoted unless it was explicitly marked as 'safe'.
- eru 15y agoDo you treat SQL queries as strings in your code, or do you build something like an abstract syntax tree?
- al_james 15y agoBuild them using a syntax builder framework, but it is possible to pass raw SQL strings in in exceptional circumstances. Obviously, the developer needs to be totally aware of the risks of this. Not ideal, but needed to solve a couple of problems.
- yesbabyyes 15y agoWith eco templates, I output strings with <%=. To output unescaped strings such as templates, I must write <%-. This works for me.