Bug #76215 [NEW]: 7.3: strip_tags deprecation of "allowed_tags"

From: Date: Fri, 13 Apr 2018 07:33:43 +0000
Subject: Bug #76215 [NEW]: 7.3: strip_tags deprecation of "allowed_tags"
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214718@lists.php.net to get a copy of this message
From: spam2 at rhsoft dot net Operating system: PHP version: Next Minor Version Package: Scripting Engine problem Bug Type: Bug Bug description:7.3: strip_tags deprecation of "allowed_tags" Description: ------------ https://wiki.php.net/rfc/deprecations_php_7_3 strip_tags() From some preliminary feedback: We might want to only deprecate the insecure allowed_tags parameter, but keep the ?strip all tags? functionality. This function appears to be useful as a relatively simple way of reusing code that outputs HTML in a different context (CLI output, text messages, etc.) what the hell do you gain with that? how is a param nobody is forced to use unsecure? i have a simple usecase which is *not* unsecure and i don't see any gain in break that: working in a WYSIWG-editor, cleanup pasted content and have a few checkboxes which tags should survive * headlines * paragraphs * <ul>, <ol>, <li> * tables default is strip everything in fact that works way better than all the existing javascript crap and in PHP it's a one-liner with a simple from-post and replace the WYSIWG-content where you could write any html code anyways in source-mode so again: what do you gain with remove functionality? -- Edit bug report at https://bugs.php.net/bug.php?id=76215&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76215&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76215&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76215&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=76215&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=76215&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=76215&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=76215&r=needscript Try newer version: https://bugs.php.net/fix.php?id=76215&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=76215&r=support Expected behavior: https://bugs.php.net/fix.php?id=76215&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=76215&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=76215&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=76215&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76215&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=76215&r=dst IIS Stability: https://bugs.php.net/fix.php?id=76215&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=76215&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=76215&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=76215&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=76215&r=mysqlcfg

« previous php.bugs (#214718) next »