Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the particular case of integer ids, however, can't you just make sure what's being passed is an integer? Similarly, for a 'simple' username, check against "^[a-zA-Z0-9]+$"?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: