Req #15972 [Ana->Wfx]: strip_tags should allow restricting the attributes on tags that are kept

From: Date: Wed, 26 May 2021 19:20:55 +0000
Subject: Req #15972 [Ana->Wfx]: strip_tags should allow restricting the attributes on tags that are kept
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234032@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=15972&edit=1

 ID:                 15972
 Updated by:         krakjoe@php.net
 Reported by:        rn214 at cam dot ac dot uk
 Summary:            strip_tags should allow restricting the attributes
                     on tags that are kept
-Status:             Analyzed
+Status:             Wont fix
 Type:               Feature/Change Request
 Package:            Strings related
 Operating System:   *
 PHP Version:        *
 Block user comment: N
 Private report:     N

 New Comment:

In the 19 years since this feature request was made, no implementation has been proposed.

I'm closing this as won't fix, as that seems to more accurately represent the status of
this request.


Previous Comments:
------------------------------------------------------------------------
[2002-05-02 16:10:58] jimw@php.net

rewrote the summary. it would be nice if the syntax were something like: strip_tags($text,
"a[href,target],br,p")

------------------------------------------------------------------------
[2002-03-09 12:08:43] rn214 at cam dot ac dot uk

Oops - that should be 

...javascript:document...

------------------------------------------------------------------------
[2002-03-09 11:56:50] rn214 at cam dot ac dot uk

The html strip_tags() function permits any attributes. This gives a security hole. Eg allowing
<b> also permits:

<b onclick="javascript.document.location='http://www.evil.com';">

That's not so nice !

Context: I run a website in which I want to allow (untrusted) users to post messages formatted with
a very limited subset of html. I don't want them to be able to do anything nasty.

I am aware that this may not really be a bug per se, and might be better as a new string function
('vanilla_tags'). But it could bite the unwary.

Thanks a lot

Richard

------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=15972&edit=1


Thread (5 messages)

« previous php.bugs (#234032) next »