Req #23723 [Ana->Csd]: strip_tags() tag blacklisting

From: Date: Thu, 07 Apr 2022 14:55:39 +0000
Subject: Req #23723 [Ana->Csd]: strip_tags() tag blacklisting
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-240765@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=23723&edit=1 ID: 23723 Updated by: ilutov@php.net Reported by: eric at evilwalrus dot com Summary: strip_tags() tag blacklisting -Status: Analyzed +Status: Closed Type: Feature/Change Request Package: Strings related Operating System: * PHP Version: * -Assigned To: +Assigned To: ilutov Block user comment: N Private report: N New Comment: This feature request has been open for a long time with no action. We're migrating away from bugs.php.net, if this is still desired please create a new issue on GitHub. Previous Comments: ------------------------------------------------------------------------ [2011-01-10 22:22:14] jthijssen at noxlogic dot nl I've added the patch base64 encoded because of a bug in php's bugtracker (bug #53703). ------------------------------------------------------------------------ [2011-01-09 21:16:09] jthijssen at noxlogic dot nl I know it's a (very) old bug, but on occasion I need a "blacklist" intead of a "whitelist" strip_tags() function. I've created a patch with an addtional bool to strip_tags() with which you can use the $allowable_tags parameter as a blacklist instead of a whitelist. Examples: strip_tags('<a>Click</a><b>here<b>', '<a>'); => <a>Click</a>here strip_tags('<a>Click</a><b>here<b>', '<a>', false); => Click<b>here</b> ------------------------------------------------------------------------ [2003-05-20 13:47:14] eric at evilwalrus dot com Right now strip_tags() is a great function. You specify a string and the tags you want to keep. What I would like to see is another argument in strip tags so that you could tell it to keep or remove the tags you specify. I saw bug #5976 that had something to do with this very thought, but this extends the idea further. For example, if I have a string full of HTML and I want to remove all <script> and <meta> tags but keep the rest, I could do something like strip_tags($string, '<meta><script>', true); That boolean value of true as the third argument would tell the strip_tags() function to remove the tags specified. Without that, it defaults to the way it is now and removes all but those tags. I think this would be a very handy thing to have in PHP. Thanks. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=23723&edit=1

« previous php.bugs (#240765) next »