Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You just accept raw strings without doing any kind of validation? The step that performs validation should encode that step in the form of a type.




i pride myself in never doing any validation ever

never escape anything, either

just hand my users a raw SQL connection


I prefer to just skip a few steps and email them my bank account number when they register an account.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: