# Charset input escape

**URL:** <https://discourse.cakephp.org/t/charset-input-escape/2251>\
**Category:** Uncategorized\
**Created:** [March 17, 2017, 5:33pm UTC](https://discourse.cakephp.org/t/charset-input-escape/2251 "2017-03-17T17:33:08Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Doshu](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/doshu/32/360_2.png) [@Doshu](https://discourse.cakephp.org/u/Doshu)\
**Post date:** [March 17, 2017, 5:33pm UTC](https://discourse.cakephp.org/t/charset-input-escape/2251/1 "2017-03-17T17:33:08Z")

</div>

A question for advanced users.

Do you use to sanitize user input from incompatible char in the used chartset? for example, if your application use utf8 encoding, when a form is submitted, do you sanitize every input from unexpeted bytes?

How do you handle this with cakephp? Cake does not have a sanitize layer such as validation. Maybe the only place to sanitize input is the beforeMarshall event.

Another option is to add a validation rule on all input (table or modelless forms).

What do you think about this problem?
