Bug #66111 [Com]: strip_tags strip <=

From: Date: Wed, 20 Nov 2013 14:46:43 +0000
Subject: Bug #66111 [Com]: strip_tags strip <=
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182863@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66111&edit=1 ID: 66111 Comment by: anon at anon dot anon Reported by: 22rist at gmail dot com Summary: strip_tags strip <= Status: Open Type: Bug Package: Filter related Operating System: windows 7 x64 PHP Version: 5.5Git-2013-11-18 (Git) Block user comment: N Private report: N New Comment: The subject is that you're misusing the function. strip_tags removes tags from HTML. This is not valid HTML: Mileage <= 15000 Now read the warning in the documentation: Because strip_tags() does not actually validate the HTML, partial or broken tags can result in the removal of more text/data than expected. I.e., garbage in = garbage out. Previous Comments: ------------------------------------------------------------------------ [2013-11-20 14:18:34] 22rist at gmail dot com The subject is "The function strip_tags should strip tags and only tags". Not "How I use strip_tags". Or "how somebody filter comments". So if you can't write something related to the subject please do not spam. ------------------------------------------------------------------------ [2013-11-20 13:59:45] anon at anon dot anon Why would someone write that? Oh wait, you just did. Can you imagine how annoying it would be for you to type your comment if this bug page used strip_tags? ------------------------------------------------------------------------ [2013-11-20 13:35:03] 22rist at gmail dot com Ok, htmlspecilachars will prevent XSS. But I want to STRIP TAGS. I want to see "Please use google.com" when user write "<b>Please</b> use <a href="https://www.google.com">google.com</a>" AND NOT an encoded variant of "<b>Please</b> use <a href="https://www.google.com">google.com</a>" as htmlspecilachars do. ------------------------------------------------------------------------ [2013-11-20 13:17:15] anon at anon dot anon There's a very easy way to prevent XSS and allow "Mileage <= 15000". It's called htmlspecialchars. ------------------------------------------------------------------------ [2013-11-20 12:23:45] 22rist at gmail dot com In security reasons (to prevent XSS) I should strip all tags in user comments. It's not a developer blog and there wont be conversation about HTML. And your comment "they want to talk about HTML." is not related to the subject. The subject is "The function strip_tags should strip tags and only tags". ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66111 -- Edit this bug report at https://bugs.php.net/bug.php?id=66111&edit=1

« previous php.bugs (#182863) next »