3 ms·
Maybe a better way to put is that you should be smart about why, when, and where to sanitize your data. A comment on a forum should not remove “‘; DO BAD THINGS
by AtNightWeCode 5y ago
Maybe a better way to put is that you should be smart about why, when, and where to sanitize your data. A comment on a forum should not remove “‘; DO BAD THINGS;”. Why would it? It is just text in probably some UTF8 encoding. No viable web framework will write it out in a raw format if you do not explicitly ask for it. In SQL you use parameters. But as I wrote in my original comment. There are several scenarios and if you work with a web, probably the most cases, where you really want to make sure that what you have stored is a clean structured canonical data representation. Not only for your security but also for third party consumers and analyzing.
I understand that everybody who sells NOSQL solutions disagree.