4 ms·
By filter, I meant server-side sanitization. Stripping "bad stuff" as you put it should be mandatory regardless. Someone can simply craft a raw post to the "act
by eksith 12y ago
By filter, I meant server-side sanitization. Stripping "bad stuff" as you put it should be mandatory regardless. Someone can simply craft a raw post to the "action" URL of the form (the handler) without loading the page at all.
As for client-side, the user has an expectation that what was entered into the form will be the end result, but this expectation is easy to meet for a vast majority of users. The edge cases tend to be solved most of the time with a live preview that also closely matches the server-side stripping of invalid/malformed content.
When no JS is available/enabled, a preview button before final submission (a la Slashdot) is usually a good idea.
- riffraff 12y ago> Stripping "bad stuff" as you put it should be mandatory regardless. Someone can simply craft a raw post to the "action" URL of the form (the handler) without loading the page at all. The second sentence is irrelevant, I am not assuming javascript checks, I already know user input is untrusted. But the first is, AFAICT, wrong: If I escape correctly all user input before using it, I don't need to strip anything (unless I want to let some HTML through). If you think escaping input is not enough, could you give me an example?