4 ms·
That is exactly my point. The way you can eliminate potential injection attacks is by not having libraries which accepts String and treat it as a sanitized inpu
by thinkharderdev 5y ago
That is exactly my point. The way you can eliminate potential injection attacks is by not having libraries which accepts String and treat it as a sanitized input. But once you do that then there is no real reason to be wary of format strings. You can use format strings to build strings, but anything that needs a string that is sanitized against some potential injection attack only accepts a type that represents that invariant.
- pron 5y ago> But once you do that then there is no real reason to be wary of format strings. But then format strings don't help you much as you can't use them to create the sanitised types. You can't sanitise the string after it's been constructed.
- thinkharderdev 5y agoRight, but there are many, many use cases for creating string in which you don't need some specific sanitization. Most of the time when I am using a format string I am not worried about sanitization.