in reply to untainting unicode text using \w
In general, if you can't strictly validate input (i.e. match it against known-good data), it's better to make the process completely indifferent to the input. In the same way that using placeholders with DBI is better than grepping on (un)safe characters.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: untainting unicode text using \w
by danmcb (Monk) on Aug 25, 2007 at 00:52 UTC |