i was wondering: when i get user data and want to store it in a table it is common knowledge that you have to sanitize it before storing it.
but as i was looking up some best practices, i read on bobby-tables.com that sanitizing is not really the way to go - you should really use parameterized SQL calls.
I have no idea what that is (yet).
But as the examples there talk about PDO and MODx is based on xPDO, i wondered if these practices are already included when i call $myObject->save();
Can anyone tell me, what best practices on user input sanitizing are?
(i would rtfm, but this is down at the moment and i don’t recall this being discussed there)
@itWilllBeOK
Ok, documentation is up again and now i know a little more, even though i’m not necessarily any smarter.
In the Explanation of Directory Structure, as well as in the tutorial ’PHP Coding in MODx’, there’s talk of connectors and processors. Connectors seem to do some user input sanitizing. Explicitly named are AJAX requests, where connectors are used, so i don’t know if they come into play when i merely save an object.
In the xPDO docs under Setting Object Fields is an example where fields are set via fromArray directly from the $_POST Array. But again i can not see if this can be construed as valid practice or if it is just a convenient example.
So again: how do people here handle user input?
@itWilllBeOK
Thank you, Jason.
This about answers the main part of my question. I was mainly concerned with storing the data in the database. I do know that sql-injection exists, but i’m not on expert on preventing it. Prepared statements are a new concept for me (on which i’m going to have to do some catching up).
So i was wondering if you already did that job for me - which, apparently, you did. As always: i very much appreciate your work. I just wanted to make sure so i wouldn’t have to do some half assed security thingy on my own, that you already did, i presume, expertly.
I’m aware that there’s still more burden on my shoulders concerning user input, and i will do my best to handle this.
Thanks again.
@itWilllBeOK