16
I am using CodeIgniter.
Recently, I read a PHP book and saw some functions to escape output to server to database using
*_escape_string()
and from server to browser using:
htmlentities()
htmlspecialchars()
In my Codeigniter application, how are these functions handled? Is it internally handled by the framework, or do I have to manually handle it?
In Ccodeigniter form validation I have seen xss_clean
$this->form_validation->set_rules('password', 'Password', 'required|xss_clean|min_length[6]|matches[confirmpassword]' );
Is xss_clean for preventing cross site scripting, or does it deal with the above I have mentioned?