Also sometimes the user might want to save code snippets in the database, would be bad to escape them.
Also sometimes the user might want to save code snippets in the database, would be bad to escape them.
Cross site scripting and sql injection attacks could almost be prevented by checking the input for the unwanted characters and in case if they got in to your system second level of defense is to html encode them when you ouput on the screen.
1. The number one reason is that it reduces programmer error. If we never store corrupted data then we're never at risk for displaying it. This is a practical concern because I've observed I and other programmers I've worked with often make errors. I have no knowledge of whether or not this is true for all programmers.
2. Nothing gets messy because we don't escape anything. Certain types of data simply aren't let in.
3. There are some edge cases where we do relax the rules, primarily for the admin user.
4. People should still be able to store code snippits but they need to escape them first.
you don't restrict all things to the same conditions. if you need to take in text that shouldn't be escaped, don't escape it. just make sure you deal with it correctly.
edit:
if that doesn't help and you still are wondering why you should sanitize inputs, read up more on xss and sql injection vulnerabilities.