We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 13218
    • 134 Posts
    i was wondering: when i get user data and want to store it in a table it is common knowledge that you have to sanitize it before storing it.

    but as i was looking up some best practices, i read on bobby-tables.com that sanitizing is not really the way to go - you should really use parameterized SQL calls.

    I have no idea what that is (yet).

    But as the examples there talk about PDO and MODx is based on xPDO, i wondered if these practices are already included when i call $myObject->save();

    Can anyone tell me, what best practices on user input sanitizing are?

    (i would rtfm, but this is down at the moment and i don’t recall this being discussed there)
      @itWilllBeOK
      • 13218
      • 134 Posts
      Ok, documentation is up again and now i know a little more, even though i’m not necessarily any smarter.

      In the Explanation of Directory Structure, as well as in the tutorial ’PHP Coding in MODx’, there’s talk of connectors and processors. Connectors seem to do some user input sanitizing. Explicitly named are AJAX requests, where connectors are used, so i don’t know if they come into play when i merely save an object.

      In the xPDO docs under Setting Object Fields is an example where fields are set via fromArray directly from the $_POST Array. But again i can not see if this can be construed as valid practice or if it is just a convenient example.

      So again: how do people here handle user input?
        @itWilllBeOK
        • 22303 MODX Staff
        • 10,725 Posts
        Quote from: itWillBeOk at Dec 03, 2010, 11:18 AM

        In the xPDO docs under Setting Object Fields is an example where fields are set via fromArray directly from the $_POST Array. But again i can not see if this can be construed as valid practice or if it is just a convenient example.

        So again: how do people here handle user input?
        MODx handles some sanitization itself, but that doesn’t mean your job as a Snippet or Plugin developer stops there.

        It just really depends on the type of input you are getting and what is considered valid input in a specific situation to be honest. But you don’t need to worry about SQL injection when using fromArray() directly from a $_POST, or any other method in xPDO. It uses prepared statements via the PDO layer, which automatically handles some sanitization. However, if you are going to, for instance, echo back out user-input, you would need to sanitize HTML tags from it to prevent potential XSS vulnerabilities.

        Writing proper input validation and sanitization is a very large and constantly changing topic, so it’s going to be hard to generalize here. You are better off asking very specific questions about particular methods of validation or sanitization for a particular scenario.
          • 13218
          • 134 Posts
          Thank you, Jason.
          This about answers the main part of my question. I was mainly concerned with storing the data in the database. I do know that sql-injection exists, but i’m not on expert on preventing it. Prepared statements are a new concept for me (on which i’m going to have to do some catching up).
          So i was wondering if you already did that job for me - which, apparently, you did. As always: i very much appreciate your work. I just wanted to make sure so i wouldn’t have to do some half assed security thingy on my own, that you already did, i presume, expertly.

          I’m aware that there’s still more burden on my shoulders concerning user input, and i will do my best to handle this.

          Thanks again.

            @itWilllBeOK