Bug #63212 [Opn->Nab]: <' breaks strip_tags()

From: Date: Mon, 30 Aug 2021 16:29:51 +0000
Subject: Bug #63212 [Opn->Nab]: <' breaks strip_tags()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236184@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=63212&edit=1

 ID:                 63212
 Updated by:         cmb@php.net
 Reported by:        dac dot chartrand at gmail dot com
 Summary:             <' breaks strip_tags()
-Status:             Open
+Status:             Not a bug
 Type:               Bug
 Package:            Strings related
 PHP Version:        5.4.7
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

strip_tags() is a crude tool, and it rather errs on the side of
caution, i.e. it may remove more than necessary.  That is even
documented[1]:

| Because strip_tags() does not actually validate the HTML,
| partial or broken tags can result in the removal of more text/data
| than expected.

So the reported behavior is not a bug.

Personally, I suggest to only use strip_tags() on valid HTML, or
better to not use the function at all.

[1] <https://www.php.net/strip_tags>


Previous Comments:
------------------------------------------------------------------------
[2012-10-10 21:36:51] willfitch@php.net

@riptide - no. <strong> is in the list of allowable tags.

I'll look into this one this evening.

------------------------------------------------------------------------
[2012-10-04 17:44:38] riptide dot tempora at opinehub dot com

"Expected result:
----------------
<strong>Hello World</strong>Should be removed<h1>Goodbye World</h1>

Actual result:
--------------
<strong>Hello World</strong>Should"

Shouldn't that <strong>(.*)</strong> be eliminated to? :\

------------------------------------------------------------------------
[2012-10-04 02:16:26] pierrick@php.net

Hi Daniel,

You're right, the ' is actually opening a quote which is never closed. But in a 
valid html/xml, having something like this : <'foo'> is now allowed. We could 
maybe verify that the node have a name before accepting an opening quote.

------------------------------------------------------------------------
[2012-10-04 01:56:16] dac dot chartrand at gmail dot com

Hi Pierrick

I disagree. Maybe my report needs more info. Here are two other examples:

-=-=-

$content = "<strong>Hello World</strong><fake>Should <# > be
removed</fake>
<h1>Goodbye World</h1>";
$content = strip_tags($content,
'<del><ins><p><div><span><hr><br><cite><strong>
<em><pre><img><a><h1><h2><h3>
<h4><h5><h6><dl><dt><dd><ul><li><ol><sub><sup><tt><blockquote><aside><table>
<thead><tbody><tfoot><tr><td>
<th>');
echo $content; 

// <strong>Hello World</strong>Should  be removed<h1>Goodbye World</h1>

$content = "<strong>Hello World</strong><fake>Should <' > be
removed</fake>
<h1>Goodbye World</h1>";
$content = strip_tags($content,
'<del><ins><p><div><span><hr><br><cite><strong>
<em><pre><img><a><h1><h2><h3>
<h4><h5><h6><dl><dt><dd><ul><li><ol><sub><sup><tt><blockquote><aside><table>
<thead><tbody><tfoot><tr><td>
<th>');
echo $content; 

// <strong>Hello World</strong>Should 

-=-=-

Thanks for looking into this.

------------------------------------------------------------------------
[2012-10-03 23:34:14] pierrick@php.net

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php

Hi Daniel,

I don't think this is a bug. You're opening a tag which is not terminated. So 
strip_tags will strip it.

If you replace your <' by any other char (but space) like <a you'll have the 
same behavior.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=63212


--
Edit this bug report at https://bugs.php.net/bug.php?id=63212&edit=1


Thread (7 messages)

« previous php.bugs (#236184) next »