We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 31037
    • 358 Posts
    Hi. I’m currently creating some snippets, including PPP.

    I’ve been thinking about what sanitization should be applied before putting stuff into the database.

    I’m currently using $modx->db->escape() but I guess that isn’t really enough.

    Will there be any problems with running the input through htmlentities()? Should I also run it through htmlspecialchars?

    As in the case with PPP, I don’t know what the users will use their table fields for. If I for example use strip_tags() I might prevent using the tables as wanted...

    Giving them the option to choose what sanitization should be used by extra parameters in the snippet call could work, but I try to make the snippet as user friendly as possible, and to many parameters are confusing.

    Also, in the case of PPP, I use eForm for input. Some sanitization could be done there, but in that case all the security would have to be done by the user of PPP, leaving all the responsability to them. Not good I guess?

    So, what combination of sanitization would work best? Without limiting the snippet too much?

    Any thoughts on this subject would be appreciated!

    Thanks!

    Anders