Recognize common web risks
Learn how input handling and browser boundaries affect web security.
- Recognize why output encoding and parameterized queries matter.
Web applications cross trust boundaries: browsers, servers, databases, and third-party services handle data from different sources. Treat external input as untrusted. Parameterized database queries keep data separate from SQL instructions. Context-aware output encoding prevents text from being interpreted as executable markup or script. Cross-site request forgery defenses help ensure a state-changing request was intentionally initiated through the expected flow; cookie settings such as SameSite are one part of the defense.
untrusted = "<script>"
print("stored as data:", repr(untrusted))
print("query placeholder: SELECT * FROM users WHERE name = ?")stored as data: '<script>' query placeholder: SELECT * FROM users WHERE name = ?
Validation helps enforce business rules, but it does not replace safe query construction or output handling. Keep dependencies and frameworks updated, and follow vendor guidance when a security issue is disclosed.
Key takeaways
Keep data and instructions separate in queries.
Encode output for the context where it is rendered.
Client-side validation cannot replace server-side controls.
Lesson quiz
5 questions · pass with 4 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…