in reply to Do I have to untaint all user input in a form?
I do most of the heavy lifting in...(gulp)... Javascript
If the client has JavaScript shut off, what do you do? JS validation should only be used to save a server request that would be rejected anyway. It doesn't end your responsibility of having to do validation server-side.
do I have to validate every user input value
Taint mode won't force you to do so, but it's a good idea.
----
I wanted to explore how Perl's closures can be manipulated, and ended up creating an object system by accident.
-- Schemer
: () { :|:& };:
Note: All code is untested, unless otherwise stated
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Do I have to untaint all user input in a form?
by bradcathey (Prior) on Nov 14, 2003 at 16:04 UTC | |
by jeffa (Bishop) on Nov 14, 2003 at 21:15 UTC | |
by sauoq (Abbot) on Nov 14, 2003 at 21:36 UTC | |
by runrig (Abbot) on Nov 14, 2003 at 22:04 UTC | |
by bradcathey (Prior) on Nov 14, 2003 at 21:39 UTC |