• Username@feddit.de
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    1
    ·
    1 year ago

    That’s not how any of this works.

    First of all, stripping passwords is never okay. You can reject the password and let the user choose a new one, but never just modify it on your own.

    Then, if your system is at risk of code injection by certain characters in user input, please just shut it down and never turn it on again.