Output encoding is context-specific
The same value needs escaping differently depending on where it is going.
Into HTML, into an attribute, into JavaScript, into a URL, into SQL. A single sanitise-on-input step cannot know the destination, which is why encoding belongs at the point of output. Getting this wrong is the reason cross-site scripting keeps appearing in applications that thought they had handled it.
More on Web application security
- CSRF abuses an authenticated browserTheir note, your session
- XSS turns trusted pages into script deliveryIt comes out in your own voice
- Path traversal escapes the intended file areaTwo dots at a time
- File upload security is more than extension checkingThe label is a claim, not a check
- Open redirects lend trusted domains to phishingYour livery, their destination
- Security headers shape browser behaviourInstructions the browser follows
