Well any sort of data that even just *might* be touched by a user should be sanitized before actually being used, whether in a GET or POST request, without exception. I usually use a function like this to initially clean my input:
function clean( $input ) {
$input = trim( $input ); //Trim whitespace
$input = mysql_real_escape_string( $input ); //Escape data to make query-safe
$input = htmlentities( $input, ENT_COMPAT, 'UTF-8' ); //Convert characters like < and & to their ASCII equivalent. Double check the charset for encoding!
return $input;
}
That’s generally enough to protect against most types of attacks (SQL injection and XSS). Of course, it’s best to also combine that with type checking too. For example, if you’re expecting a variable to only contain an id or numerical value, use either is_numeric to check the type, or intval to cast the input to an integer (so something like "aa\2" would become "2". If a value should be a certain length, check the length using strlen. You could even use preg_replace to strip out characters other than those expected which is also a pretty good method. For some of my own scripts, I use an array to populate a dropdown list. If you compare the actual user input against the values in the array using in_array, then that’s yet another good way to prevent "bad" data from being inputted.
Edit: I forgot to mention that the $modx->db->escape() function does the same thing as mysql_real_escape_string.