3 ms·
Alternatively... validate (client side) => insert using sql parameterization (escaping) => escape per context when outputting Sanitizing is the idea that you
by InitialBP 5y ago
Alternatively...
validate (client side) => insert using sql parameterization (escaping) => escape per context when outputting
Sanitizing is the idea that you are cleaning dangerous things from the original input (different than validating which is disallowing user's to input characters that don't conform to what your program expects).
One BIG issue here is that validation is generally clear to the user ("That is an invalid email address") whereas sanitization normally doesn't consult or inform the user that there were changes and may result in unexpected things happening from a user perspective.
From article: name is "John O'Brien" now displays as "John OBrien" (this is a trivial example but still an issue)
The name thing is a great example of things you might not expect your users to do but are still totally valid use cases. Sanitization can be Extremely frustrating from a user perspective.