Bug #66111 [Opn->Nab]: strip_tags strip <=
| From: | johannes@php.net | Date: | Wed, 20 Nov 2013 14:54:51 +0000 |
| Subject: | Bug #66111 [Opn->Nab]: strip_tags strip <= | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182864@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66111&edit=1
ID: 66111
Updated by: johannes@php.net
Reported by: 22rist at gmail dot com
Summary: strip_tags strip <=
-Status: Open
+Status: Not a bug
Type: Bug
Package: Filter related
Operating System: windows 7 x64
PHP Version: 5.5Git-2013-11-18 (Git)
Block user comment: N
Private report: N
New Comment:
Browsers are quite error tolerant in parsing HTML. strip_tags tries to be secure with the risk of
breaking input. If you want to take data into HTML and want the browser to render it properly use
htmlentities etc.
Previous Comments:
------------------------------------------------------------------------
[2013-11-20 14:46:43] anon at anon dot anon
The subject is that you're misusing the function. strip_tags removes tags from HTML. This is
not valid HTML:
Mileage <= 15000
Now read the warning in the documentation:
Because strip_tags() does not actually validate the HTML, partial or
broken tags can result in the removal of more text/data than expected.
I.e., garbage in = garbage out.
------------------------------------------------------------------------
[2013-11-20 14:18:34] 22rist at gmail dot com
The subject is "The function strip_tags should strip tags and only tags".
Not "How I use strip_tags". Or "how somebody filter comments".
So if you can't write something related to the subject please do not spam.
------------------------------------------------------------------------
[2013-11-20 13:59:45] anon at anon dot anon
Why would someone write that?
Oh wait, you just did. Can you imagine how annoying it would be for you to type your comment if this
bug page used strip_tags?
------------------------------------------------------------------------
[2013-11-20 13:35:03] 22rist at gmail dot com
Ok, htmlspecilachars will prevent XSS. But I want to STRIP TAGS.
I want to see
"Please use google.com"
when user write
"<b>Please</b> use <a href="https://www.google.com">google.com</a>"
AND NOT an encoded variant of "<b>Please</b> use <a href="https://www.google.com">google.com</a>"
as htmlspecilachars do.
------------------------------------------------------------------------
[2013-11-20 13:17:15] anon at anon dot anon
There's a very easy way to prevent XSS and allow "Mileage <= 15000". It's
called htmlspecialchars.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66111
--
Edit this bug report at https://bugs.php.net/bug.php?id=66111&edit=1