Quantcast
Channel: Adobe Community : Unanswered Discussions - ColdFusion
Viewing all articles
Browse latest Browse all 5794

Using ESAPI in CF10/11 for sanitizing input

$
0
0

Hello, all,

 

The boss has given me the green light for getting rid of Portcullis in favor of ESAPI.  GREAT!!

 

But all the documentation I've been looking at isn't really helping me to implement it.

 

What we did have set up with Portcullis was in Application.cfc.  During the onRequestStart(), it checked to see if Portcullis was defined (init it if it wasn't), then passed URL and FORM scopes to Portcullis for scanning.  If Portcullis found something that shouldn't be there, it redirected to the home page.

 

I'm leaning towards using ESAPI for sanitizing input, not detecting and redirecting.  Is there a way to set ESAPI up to scan entire FORM or URL scoped values within the Application.cfc?   Or am I doomed to going to every form processing page and adding the sanitization to every form or url value?

 

V/r,

 

^_^


Viewing all articles
Browse latest Browse all 5794

Trending Articles


Practice Sheet of Right form of verbs for HSC Students


TYKEMA GLEATON


The Conjuring 2 (Tamil Dubbed)


Woman stabbed 12 times and dumped in ditch


Moondru Mudichu 07-06-2016 – Polimer tv Serial


Trio remanded on gun, other serious charges


Rick Ross & Etana – Kiss Of Judas – Single [iTunes Plus M4A]


The 6 Best Sex Scenes in Nollywood Movies


Take this week's NJ.com Local News Quiz


Angeline Yap kym?



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>