Daniel Convissor wrote:
Hi Rob:

On Mon, Nov 12, 2007 at 04:26:54PM -0500, Rob Marscher wrote:
But it's expensive to escape it every time someone views the page. Therefore, it's recommended to filter it on input but store the filtered version

This approach is flawed because disgruntled people who have server side access to the database can insert HTML. Escaping HTML upon page generation is the safest way to go.

--Dan

Exactly! All input is evil, even when it comes from your database and your script. There is no good reason not to check input each and every time, there are only bad excuses for not doing it.

David
_______________________________________________
New York PHP Community Talk Mailing List
http://lists.nyphp.org/mailman/listinfo/talk

NYPHPCon 2006 Presentations Online
http://www.nyphpcon.com

Show Your Participation in New York PHP
http://www.nyphp.org/show_participation.php

Reply via email to