I think I found the issue.
I think I found the issue.
Think of every language as a strictly typed, pure functional programming language, where I/O is the big bad world out there and evil and blocking and complicated. Likewise, on the web you should treat any inputs as being evil... (ok, so the comparison is far from perfect, but the idea holds true)
If you ever put "you just need" into a sentence about security you've already lost.
User input need to be sanitized always. Rails make it easy and is the default way.
Regardless, it's not a knock on rails. Just saying it's not necessarily a magic bullet to secure apps (and I don't believe rails nor PHP needs to be).
Edit: It's not actually a footnote -- it's actually just the only item on the lonesome "Security" page.
Which is why you should never process raw input in multiple places in your app. One method I've used for over a decade of webdev in any language: there's only one place to get the input from, and that place requires you specify what input is allowed.
While this may be not as easy to use as simple strings, it is consistent.
Honestly, I'm trying to figure out how someone could sanitize their input and still be affected by this.
I don't think you could, unless you tried to write your own sanitizing functions from scratch and somehow screwed it up. In PHP, htmlspecialchars(), mysql_real_escape_string() and addslashes() all do fine sanitizing array input -- either throwing an exception or returning the string "Array".