in reply to Re: Re: Do I have to untaint all user input in a form?
in thread Do I have to untaint all user input in a form?
UPDATE:
I can admit that what sauoq says is good -
if you do have some expensive submission that will benefit
from being validated on the client side first, well ...
go for it. Some redundancy isn't so bad, especially when
you compare the chore of keeping it consistant to ...
washing dishes. :D It just ain't so bad after all. ;)
jeffa
L-LL-L--L-LL-L--L-LL-L-- -R--R-RR-R--R-RR-R--R-RR B--B--B--B--B--B--B--B-- H---H---H---H---H---H--- (the triplet paradiddle with high-hat)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: 3Re: Do I have to untaint all user input in a form?
by runrig (Abbot) on Nov 14, 2003 at 22:04 UTC | |
|
Re: 3Re: Do I have to untaint all user input in a form?
by sauoq (Abbot) on Nov 14, 2003 at 21:36 UTC | |
|
Re: 3Re: Do I have to untaint all user input in a form?
by bradcathey (Prior) on Nov 14, 2003 at 21:39 UTC |