Validating user input?

后端 未结 3 409
走了就别回头了
走了就别回头了 2021-01-18 18:10

I am very confused over something and was wondering if someone could explain.

In PHP i validate user input so htmlentitiies, mysql_real_escape_string is used before

3条回答
  •  佛祖请我去吃肉
    2021-01-18 18:41

    There's no reason to worry about having malicious JavaScript code in the database if you're escaping the HTML when it comes out. Just make sure you always do escape anything that comes out of the DB.

提交回复
热议问题