Re: Is data sanitization required in setting $this->Model->id = $id?

2013-06-14 Thread John
Sorry I don't get if your answer means it should or shouldn't be used directly :) On Wednesday, June 12, 2013 9:35:10 AM UTC+3, Simon Males wrote: > > I think that is a fair call. > > > On Tue, Jun 11, 2013 at 1:22 AM, John >wrote: > >> Say I get the $id from a url, /controller/action/id and want

Re: Is data sanitization required in setting $this->Model->id = $id?

2013-06-11 Thread Simon Males
I think that is a fair call. On Tue, Jun 11, 2013 at 1:22 AM, John wrote: > Say I get the $id from a url, /controller/action/id and want to use it to > do a $this->Model->id = $id. > > Is it safe to pass it as it's coming in or do I need to call Sanitize:: > clean first? The book mentions that

Is data sanitization required in setting $this->Model->id = $id?

2013-06-10 Thread John
Say I get the $id from a url, /controller/action/id and want to use it to do a $this->Model->id = $id. Is it safe to pass it as it's coming in or do I need to call Sanitize::cleanfirst? The book mentions that if you use cake's ORM you're safe, but I couldn't follow the code enough to find out