3 ms·
They're calling the SQL query "output" (from the app to the DB server). The point is that the "bad characters" depend on the context, so it's the step where you
by kam 5y ago
They're calling the SQL query "output" (from the app to the DB server). The point is that the "bad characters" depend on the context, so it's the step where you combine trusted and untrusted data that you need to think about escaping or validating.
- gkoberger 5y agoNo they're not. They're using the word "output" to mean "back into the HTML". "So the better approach is to store whatever name the user enters verbatim, and then have the template system HTML-escape when outputting HTML, or properly escape JSON when outputting JSON and JavaScript."
- kam 5y agoThe sentence immediately after that is "And of course use your SQL engine’s parameterized query features so it properly escapes variables when building SQL"