Jeff Moore's blog has this new post today concerning "The Usability of Input Filtering" and a few examples scenarios.
There seems to be much interest lately in input filtering in PHP, especially in cross site scripting prevention. I've always preferred input validation to input filtering, but I am giving filtering a new examination. My problem with filtering is with usability. The comments to this post are a good example. There are obviously some usability issues going on here.
Some of the examples include: Direct Filter, Filter with Preview, Filter with Buffered Preview, Filter with Forced Preview, Filter with Confirmation and Warning, and Validation. In each example, he gives a quick glance into what would make it work and an example of where it might be found.




