Friday, June 14, 2013

Re: Is data sanitization required in setting $this->Model->id = $id?

Sorry I don't get if your answer means it should or shouldn't be used directly :)

On Wednesday, June 12, 2013 9:35:10 AM UTC+3, Simon Males wrote:
I think that is a fair call.


On Tue, Jun 11, 2013 at 1:22 AM, John <spi...@gmail.com> wrote:
Say I get the $id from a url, /controller/action/id and want to use it to do a $this->Model->id = $id.

Is it safe to pass it as it's coming in or do I need to call Sanitize::clean first? The book mentions that if you use cake's ORM you're safe, but I couldn't follow the code enough to find out how it is sanitized :)

--
Like Us on FaceBook https://www.facebook.com/CakePHP
Find us on Twitter http://twitter.com/CakePHP
 
---
You received this message because you are subscribed to the Google Groups "CakePHP" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cake-php+u...@googlegroups.com.
To post to this group, send email to cake...@googlegroups.com.
Visit this group at http://groups.google.com/group/cake-php?hl=en.
For more options, visit https://groups.google.com/groups/opt_out.
 
 



--
Simon Males

--
Like Us on FaceBook https://www.facebook.com/CakePHP
Find us on Twitter http://twitter.com/CakePHP
 
---
You received this message because you are subscribed to the Google Groups "CakePHP" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cake-php+unsubscribe@googlegroups.com.
To post to this group, send email to cake-php@googlegroups.com.
Visit this group at http://groups.google.com/group/cake-php.
For more options, visit https://groups.google.com/groups/opt_out.
 
 

No comments: