What's the best, Escape then store Or store then escape the output?
Posted
by Axel
on Stack Overflow
See other posts from Stack Overflow
or by Axel
Published on 2010-04-01T23:47:24Z
Indexed on
2010/04/01
23:53 UTC
Read the original article
Hit count: 280
Hi, After doing a long search on stackoverflow i didn't find any one talked about this even if it's a big choice, the Question is what's the best in order to prevent both of XSS and SQL injection, Escaping the data then store it in the DB or Store it as it is and escape when output it?
Note: it is better if you give some examples of practics if possible.
Thanks
© Stack Overflow or respective owner