4 ms·
No, garbage in, garbage out. Sure, things like log or SQL injections should not only be solved by sanitizing. You solve it by separating data and code. A lot of
by AtNightWeCode 5y ago
No, garbage in, garbage out. Sure, things like log or SQL injections should not only be solved by sanitizing. You solve it by separating data and code. A lot of times you really want to store data in a structured canonical way. Usernames for instance. It is bad if you with Unicode trickery can create multiple usernames that looks the same. Product descriptions, it is bad if your ML needs to handle HTML and so on.
- kevincox 5y agoThis is wrong. If I leave a comment `'; DROP TABLE users; --` You should display it back in the app as exactly that. If you put it into an HTML attribute you escape the `'` and if you stick it in SQL you use parametrized statements. There is nothing "wrong" with that initial input. What is wrong is pasting it into an SQL string, HTML element, HTML attribute, URL parameter or anywhere else without properly encoding it. This is the main reason you can't "sanitize" input. You need to know what the output format is to properly encode it. There are different requirements if you are pasting it into a sed replacement command vs HTML attribute vs HTML element body. You can strip everything except a-zA-Z and cross your fingers but even that isn't necessarily sufficient for all output formats.
- ehutch79 5y agousing parameterized statements is sanitizing inputs into the database.
- kevincox 5y agoThe database is "outside" of your application server. You communicate with the database using statements and when you get the value back from the database it is unchanged. The encoding was just for transfer, no data has actually been changed.
- AtNightWeCode 5y agoMaybe a better way to put is that you should be smart about why, when, and where to sanitize your data. A comment on a forum should not remove “‘; DO BAD THINGS;”. Why would it? It is just text in probably some UTF8 encoding. No viable web framework will write it out in a raw format if you do not explicitly ask for it. In SQL you use parameters. But as I wrote in my original comment. There are several scenarios and if you work with a web, probably the most cases, where you really want to make sure that what you have stored is a clean structured canonical data representation. Not only for your security but also for third party consumers and analyzing. I understand that everybody who sells NOSQL solutions disagree.