N
N
Nomy Co2019-05-23 14:11:53
Information Security
Nomy Co, 2019-05-23 14:11:53

What special characters need to be disabled for input in Input?

Maybe someone has their own tables of special characters that you definitely need to disable for input in inputs? For example, in such fields as Logs and Password. I would be grateful if you throw it off, because I found a lot of tables, but they are very pancake and contain unnecessary information.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
D
dollar, 2019-05-23
@NomyCo

It is necessary to prohibit all characters, except for characters from the white list of the type a-zA-Z0-9_
The check must be on the server. On the client, verification is needed, only in order not to reload the page once again.

L
Lazy @BojackHorseman, 2019-05-23
Tag

the login must be a valid identifier, and the password has no restrictions, except for the length

T
ThunderCat, 2019-05-23
@ThunderCat

It is almost useless to forbid anything to be entered into the inputs, checks in any case should work on the principle of filtering / validating all user-entered data on the server. Entering "forbidden" data into an input or simply sending it to the server without any input is not a problem at all.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question