Bug #64430 [Opn->Nab]: strip_tags() clobbers non-tag entities
| From: | cmb@php.net | Date: | Wed, 07 Oct 2020 15:21:37 +0000 |
| Subject: | Bug #64430 [Opn->Nab]: strip_tags() clobbers non-tag entities | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229452@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64430&edit=1
ID: 64430
Updated by: cmb@php.net
Reported by: gdataonline at gmail dot com
Summary: strip_tags() clobbers non-tag entities
-Status: Open
+Status: Not a bug
Type: Bug
Package: Strings related
Operating System: Windows 7 x64
PHP Version: 5.4.13
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
strip_tags() does not validate the HTML, and works along the lines
of "better safe than sorry", so this is expected behavior, which
is also documented[1]:
| Because strip_tags() does not actually validate the HTML,
| partial or broken tags can result in the removal of more text/data
| than expected.
[1] <https://www.php.net/manual/en/function.strip-tags.php>
Previous Comments:
------------------------------------------------------------------------
[2015-03-31 10:42:59] marcosgdf at gmail dot com
I'm having the same problem.
Test script:
---------------
<?php
var_dump(strip_tags('This is not HTML, <email@email.com> is not a valid tag'));
Expected result:
----------------
string(54) "This is not HTML, <email@email.com> is not a valid tag"
Actual result:
--------------
string(37) "This is not HTML, is not a valid tag"
------------------------------------------------------------------------
[2013-03-15 19:55:52] gdataonline at gmail dot com
I'm starting to suspect that strip_tags treats anything that matches <[^>\s]*> as an
HTML tag, regardless of where it appears or if it's valid HTML.
------------------------------------------------------------------------
[2013-03-15 15:15:58] gdataonline at gmail dot com
Description:
------------
strip_tags() will clobber all remaining input after encountering non-HTML tags, regardless if
embedded in "allowable-tags".
When strip_tags() encounters a "<" followed by *any non-whitespace*, it assumes
it's an HTML tag, even if it couldn't legally be one. In the example below, even
something as simple as a "<=" appearing in JavaScript is enough to trigger the
behavior.
For a full list of characters that strip_tags() clobbers on, see this example: http://ideone.com/BEPINI
Test script:
---------------
<?php
// Example 1: Without <=
$code = "<script>if (foo >= bar){ alert(0); }</script>";
var_dump(strip_tags($code));
var_dump(strip_tags($code, "<script>"));
// Example 2: With <=
$code = "<script>if (foo <= bar){ alert(0); }</script>";
var_dump(strip_tags($code));
var_dump(strip_tags($code, "<script>"));
?>
Expected result:
----------------
string(28) "if (foo >= bar){ alert(0); }"
string(45) "<script>if (foo >= bar){ alert(0); }</script>"
string(28) "if (foo <= bar){ alert(0); }"
string(45) "<script>if (foo <= bar){ alert(0); }</script>"
Actual result:
--------------
string(28) "if (foo >= bar){ alert(0); }"
string(45) "<script>if (foo >= bar){ alert(0); }</script>"
string(8) "if (foo "
string(16) "<script>if (foo "
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64430&edit=1