Artwork
iconShare
 
Manage episode 484483414 series 2974897
Content provided by Joel Clermont and Aaron Saray. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Joel Clermont and Aaron Saray or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

Joel and Aaron dig into Laravel’s `Stringable` class and uncover how it can silently skip Blade’s automatic HTML escaping. They explain why that’s both a convenient feature and a potential security pitfall if user input isn’t properly sanitized. You’ll hear practical ways to keep your views safe without losing the API’s fluency.

  • (00:00) - Stringable can sidestep Blade escaping
  • (03:45) - Dangers of outputting unsanitized HTML
  • (05:45) - Defensive strategies for safe rendering
  • (08:45) - Silly bit

Sign up for a short, but useful, Laravel tip each day in our newsletter
  continue reading

141 episodes