Here's a lovely function defined in a module offered for contribution...
Today this arrived on my desk...
This snippet was from code that was about to create a new node. The body of this node came in via an external XML/RSS feed.
OK buddy, you may trust this source but can you expect everyone you are going to share your module with should inherit your implict trust?
In fact, I saw this in two CVS applications today. Both declined (for more than just this).
In a previous post< we have described in some detail various aspects of selecting nodes and terms ensuring that Drupal's node access system is respected. However, new and exciting examples continue to arrive at the CVS review doorstep.
Here's some more fopars we deal with on a regular basis...