Input validation defines what the application accepts
Validation is a statement about what you will accept, and the strict version is far safer than the clever version.
Listing what is allowed is robust. Trying to detect and strip what is dangerous is a game you lose eventually, because there is always another encoding. Deciding the acceptable shape, length and character set up front and rejecting everything else removes most of the argument.
More on Secure development
- Threat modelling asks how a design can fail before code existsBreak it on paper first
- Security requirements are product requirementsThey go on the same sheet
- Code review and automated scanning see different risksThe magnet and the eye
- Security tests should exercise abuse casesThe load nobody specified
- Feature flags can become security statesSomebody left it up
- Error handling should fail predictablyBreak the same way every time
