Matthias Wimmer schrieb: > I'd check for invalid characters when converting data from the UI to the > Application-Backend in methods of the backend. But I would not filter, > but reject function/method containing invalid characters. Read: ... reject function/method *calls* containing invalid characters.