in reply to Re: Do I have to untaint all user input in a form?
in thread Do I have to untaint all user input in a form?
JS validation should only be used to save a server request that would be rejected anyway.Which is precisely the way I intend to use it (now that I catching the security mojo here at PMs). Until I started coming to the monastery, I never met anyone who turned off javascript. And for those who don't, which is probably the average surfer—good or bad, client-side validation can very quickly check values, and limit the server side checks, which take more time and have to refresh screens, etc.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
3Re: Do I have to untaint all user input in a form?
by jeffa (Bishop) on Nov 14, 2003 at 21:15 UTC | |
by sauoq (Abbot) on Nov 14, 2003 at 21:36 UTC | |
by runrig (Abbot) on Nov 14, 2003 at 22:04 UTC | |
by bradcathey (Prior) on Nov 14, 2003 at 21:39 UTC |