Re: FN-FORUM: PHP PostData security
date posted 29th May 2007 18:23
>> Which aspect of the MVC pattern protects against SQL injection, and
>> which aspect stops cross-site scripting?
>
> None of it. I didn't say the MVC pattern *provided* security in depth, I
> said it *facilitated* security in depth.
Of course, I agree. I thought Mike A was implying that using MVC
automatically made your application secure, when in fact that wasn't what
he was saying at all (and I don't think he was really talking about MVC
anyway, but multi-layered architectures).
Cheers!
Anthony
--
www.fonant.com - Quality web sites