Encoding and Sanitization Architecture
V1.1.1
Verify that input is decoded or unescaped into a canonical form only once, it is only decoded when encoded data in that form is expected, and that this is done before processing the input further, for example it is not performed after input validation or sanitization.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 120, 126, 152, 153, 160, 242, 267, 28, 3, 43, 64, 71, 72, 78, 79, 80, 88
V1.1.2
Verify that the application performs output encoding and escaping either as a final step before being used by the interpreter for which it is intended or by the interpreter itself.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 120, 152, 153, 242, 267, 28, 43, 64, 71, 72, 78, 79, 80, 88
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.