in reply to Re: Re (tilly) 2: Opinions needed on CGI security
in thread Opinions needed on CGI security
Constructing a character class that filters out bad stuff is trivial. On the other hand, constructing a hack-proof set of regexen that permit specific combinations of characters while disallowing others (as in allow <a> but disallow <script> while allowing '<' and '>' if inside a code block) is far from easy.
Everything's implementation of the latter is something you might want to take a look at.
MeowChow s aamecha.s a..a\u$&owag.print
|
|---|