Security › Web Application Security
Input Sanitization
Cleaning untrusted input, and why validation and escaping matter more.
Also known as: sanitizing input, input cleaning, sanitisation
Sanitization means cleaning untrusted input by removing or changing parts of it, for example stripping <script> tags from a comment. The tempting idea is “clean everything on the way in and it’s safe”.
That idea is the classic mistake. Safety depends on where the data ends up, and at input time you don’t know:
- In an HTML page,
<must become<. - In a SQL query, a quote is the problem.
- In a shell command,
;and$()are. - In a plain text email, none of those matter and mangling them corrupts the data.
A name like O'Brien is fine data, but a blanket “remove quotes” filter breaks it, and filters like that are often bypassed anyway.
What to do instead
- Validate input against what you expect: type, length, range, allowed characters. Reject what doesn’t fit.
- Use the right defence at the point of use:
- SQL: parameterized queries, never string concatenation. See SQL injection.
- HTML: output encoding, usually done by your template engine. See XSS.
- Sanitize only when you must accept rich input, such as user-written HTML, and then use a maintained sanitizer library with an allow-list. Don’t write regexes to strip tags.
# Wrong: trying to clean the string
q = "SELECT * FROM users WHERE name = '" + name.replace("'", "") + "'"
# Right: the driver keeps data and code separate
cur.execute("SELECT * FROM users WHERE name = %s", (name,))
(The placeholder style, %s here, depends on the database driver.)