# Output Encoding

> A mechanism that escapes values for the context they are written into, such as HTML, SQL or a shell.

Record: `architecture:output-encoding`
Kind: mechanism
Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)
Severity: mandatory
Scope: UI, API, serialization
Canonical: https://banes-lab.com/ontology#architecture-output-encoding

Listed in [Architecture principles](https://banes-lab.com/api/records/architecture.md), after [Input Validation](https://banes-lab.com/records/architecture/input-validation.md) and before [Encryption at Rest](https://banes-lab.com/records/architecture/encryption-at-rest.md).

## Repair

- Refactored by: Encode Output, Use Safe Templates
- Detected by: raw HTML/SQL/shell output paths
- Violated by: unescaped user-controlled output
- Measured by: unsafe sink count
- Enforced by: security linting

## Requires

- [Context-Aware Encoding](https://banes-lab.com/records/lexicon/context-aware-encoding.md)

## Reinforces

- [Injection Prevention](https://banes-lab.com/records/lexicon/injection-prevention.md)

## Enables

- [Safe Rendering](https://banes-lab.com/records/lexicon/safe-rendering.md)

## Conflicts with

- [Raw Output Rendering](https://banes-lab.com/records/lexicon/raw-output-rendering.md)

## In tension with

- [Formatting Flexibility](https://banes-lab.com/records/lexicon/formatting-flexibility.md)

## Tensions

- [Output Encoding / Formatting Flexibility](https://banes-lab.com/records/tension/formatting-flexibility-output-encoding.md)

## Severity

- [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)

## Category

- [Security / Privacy / Compliance / Governance](https://banes-lab.com/records/architecture-category/security-privacy-compliance-governance.md)

## Linked from

- [Security Privacy Compliance](https://banes-lab.com/ontology/lexicon/lexicon-category-security-privacy-compliance.md)
- [Severity levels](https://banes-lab.com/ontology/schema/the-vocabulary-severity.md)
- [The resolutions](https://banes-lab.com/ontology/schema/the-resolutions.md)
