User Input Sanitization
The cluster focuses on the importance of sanitizing and validating user inputs in software development to prevent security vulnerabilities, with debates on whether to sanitize inputs or escape outputs and the rule of never trusting user data.
Activity Over Time
Top Contributors
Keywords
Sample Comments
They didn't sanitize their input data.. that's the worst sin you can commit.
"Unsafe input" is not a thing.
because every developer has been told to never trust user input, and to sanitize the hell out of it.
Only if you are getting input from untrusted users
Apparently somebody doesn't know how to sanitize input.
They really mean it when they say "never trust user input".
#1 rule of web app development (as far as i'm concerned): sanitize inputs. if you don't know if inputs are already/automatically sanitized, sanitize them again anyway.
Just think a virus, you know they're not going to be correctly sanitizing their inputs.
That's quite a lot of words for saying: "don't trust user input".
I've heard people being told 'sanitize your inputs!' too many times. The advice should be 'escape your outputs!'.