Bug #66111 [Com]: strip_tags strip <=

From: Date: Wed, 20 Nov 2013 15:02:05 +0000
Subject: Bug #66111 [Com]: strip_tags strip <=
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182865@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66111&edit=1

 ID:                 66111
 Comment by:         22rist at gmail dot com
 Reported by:        22rist at gmail dot com
 Summary:            strip_tags strip <=
 Status:             Not a bug
 Type:               Bug
 Package:            Filter related
 Operating System:   windows 7 x64
 PHP Version:        5.5Git-2013-11-18 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

I want to filter string writen by user
"<b>Best car ever!<b/> Mileage <= 15000"
so it looks like
"Best car ever! Mileage <= 15000";
I want to strip only tags. PHP can't do it using native functions?


Previous Comments:
------------------------------------------------------------------------
[2013-11-20 14:54:50] johannes@php.net

Browsers are quite error tolerant in parsing HTML. strip_tags tries to be secure with the risk of
breaking input. If you want to take data into HTML and want the browser to render it properly use
htmlentities etc.

------------------------------------------------------------------------
[2013-11-20 14:46:43] anon at anon dot anon

The subject is that you're misusing the function. strip_tags removes tags from HTML. This is
not valid HTML:

    Mileage <= 15000

Now read the warning in the documentation: 

    Because strip_tags() does not actually validate the HTML, partial or
    broken tags can result in the removal of more text/data than expected.

I.e., garbage in = garbage out.

------------------------------------------------------------------------
[2013-11-20 14:18:34] 22rist at gmail dot com

The subject is "The function strip_tags should strip tags and only tags".
Not "How I use strip_tags". Or "how somebody filter comments". 
So if you can't write something related to the subject please do not spam.

------------------------------------------------------------------------
[2013-11-20 13:59:45] anon at anon dot anon

Why would someone write that?

Oh wait, you just did. Can you imagine how annoying it would be for you to type your comment if this
bug page used strip_tags?

------------------------------------------------------------------------
[2013-11-20 13:35:03] 22rist at gmail dot com

Ok, htmlspecilachars will prevent XSS. But I want to STRIP TAGS. 

I want to see 
"Please use google.com"
when user write
"<b>Please</b> use <a href="https://www.google.com">google.com</a>"
AND NOT an encoded variant of "<b>Please</b> use <a href="https://www.google.com">google.com</a>"
as htmlspecilachars do.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=66111


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=66111&edit=1


Thread (13 messages)

« previous php.bugs (#182865) next »