2021年3月2日星期二

Filter input/htmlentities is necessary when using prepared statements?

When i'm using prepared statements...

1 - Should i use filter inputs? (eg. validade int/sanitize strings) 2 - Should i use htmlentities() when outputing the data from database?

Or filter input still increase the security for the web online application?

Thank you.

https://stackoverflow.com/questions/66450119/filter-input-htmlentities-is-necessary-when-using-prepared-statements March 03, 2021 at 10:55AM

没有评论:

发表评论