Joined: Aug 29, 2004 Posts: 9133 Location: Arizona
Posted:
Wed Nov 15, 2006 11:23 am
I have to agree with technocrat. When you filter data coming OUT of the database, then you have tied the hands of the admin as to what they can do with their site content. I know that this goes against the "common wisdom" out there in "security land", and I have read several very good books on PHP Security and web security in general.
IMO, one needs to be 100% certain of what gets INTO the database - i.e., ensuring no "garbage in". If you want to add 3rd party add-ons, you, as the site owner/admin, are responsible to ensure these do not open up security holes.
Like I said, this is JMO, and does not follow conventional security wisdom, but I do not believe in putting on "content hand-cuffs" on the site admin.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum