> Developers: Sanitize user input
No, don't sanitize user input. Don't trust it, which is a big difference. Use bound parameters and this problem goes away.
No, don't sanitize user input. Don't trust it, which is a big difference. Use bound parameters and this problem goes away.
Anything else is madness. Of course, if you're dealing with legacy systems you might have to do something tragic like not allow people to put quotes in passwords.