4 ms·
Then why is parameter query safer? And not just escapes variables? Escaping is hard, as shown in the article
by furstenheim 5y ago
Then why is parameter query safer? And not just escapes variables? Escaping is hard, as shown in the article
- asddubs 5y agogenerating html using find and replace/regex safely is hard. escaping is easy. and the solution is to just not generate html using find and replace. You'll run into the exact same problem trying to do a bbcode/markdown/whatever parser using javascript