• I've never yet seen an application correctly validate all the data being fed in through it. Most? Sure. All? No way.

    Just ran into a situation where "the data format is controlled by the front end" was the policy. But someone using a browser with Java scripting turned off managed to bypass all the data validation and put junk data that violated almost every business rule in the place.

    - Gus "GSquared", RSVP, OODA, MAP, NMVP, FAQ, SAT, SQL, DNA, RNA, UOI, IOU, AM, PM, AD, BC, BCE, USA, UN, CF, ROFL, LOL, ETC
    Property of The Thread

    "Nobody knows the age of the human race, but everyone agrees it's old enough to know better." - Anon