Input validation defines what the application accepts

Validation is a statement about what you will accept, and the strict version is far safer than the clever version.

Listing what is allowed is robust. Trying to detect and strip what is dangerous is a game you lose eventually, because there is always another encoding. Deciding the acceptable shape, length and character set up front and rejecting everything else removes most of the argument.

More on Secure development