Sawan<br />SCJP,SCWCD,SCBCD<br /> <br />Every exit is an entry somewhere.
Filter is a good option. You can pre process request. If user enters space and space or + or & it may be sent as different characters to the server. So how do you catch the value of attribute name=first name. It will be sent as first+name. Now if user enter first na+me how do we interpret first+na+me which is coming to server?
I feel you have to user Url encoding at client and decoding at the filter in each text field user enters if java script is not viable.