Re: Re: Injection vulnerabilities
| From: | Guilliam Xavier | Date: | Mon, 24 May 2021 13:52:01 +0000 |
| Subject: | Re: Re: Injection vulnerabilities | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-114564@lists.php.net to get a copy of this message | ||
On Fri, May 21, 2021 at 11:21 PM Craig Francis <craig@craigfrancis.co.uk>
wrote:
> [...]
>
> We need something that libraries will (in the future) be able to use to
> protect themselves against these mistakes... by all programmers, especially
> those who aren't using static analysis.
>
Hi,
Not sure what kind of answer you expect... Are you suggesting to provide
one or both of:
1. a way to forbid "dynamic" strings (or at least detect them)?
2. "safe" HTML, SQL and OS-command builder/generator/executor APIs (that
would internally restrict/validate their "static" parts and quote/escape
the dynamic parameters)?
Regards,
--
Guilliam Xavier