Hacker News new | ask | show | jobs
by serious_habit 1624 days ago
Even better- never sanitize your data.

You should only use templating systems which safely handle user data. Don't use innerHTML assignments, don't concatenate user data into SQL queries. Use existing, validated libraries for generating HTML and SQL.