In general, if you can't strictly validate input (i.e. match it against known-good data), it's better to make the process completely indifferent to the input. In the same way that using placeholders with DBI is better than grepping on (un)safe characters.
In reply to Re: untainting unicode text using \w
by Joost
in thread untainting unicode text using \w
by danmcb
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |