Re: Removing security-problematic chars from strings
| From: | Chris Shiflett | Date: | Fri, 21 Nov 2003 16:47:09 +0000 |
| Subject: | Re: Removing security-problematic chars from strings | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-170594@lists.php.net to get a copy of this message | ||
--- "CPT John W. Holmes" <holmes072000@charter.net> wrote:
> > Let's make this personal: what would be your answer if I would
> > advice the friendly person to do this:
>
> Heh.. I hope you're just kidding about "making it personal".
I think it might be a language subtlety that wasn't intended to mean what
we think it means. :-) I think he just meant that he wanted to get
specific or something like that.
> I'm against letting users enter HTML in their data, also. I'd rather
> emply a bbcode type solution, turning [b] into <b>, etc. This way, YOU
> set the rules and say the user can do these _5_ things in this exact
> syntax. Otherwise you're held at the mercy of the HTML and browser
> specs and hoping that even just allowing <b> in the future won't have
> any security issues. When _you_ set the rules, you win.
I disagree with John here, but that's OK. :-) We seem to have different
perspectives about this bbcode stuff. Personally, I see no need to define
a new markup language that you intend to convert to HTML anyway. It is an
unnecessary complication that yields no benefits from what I can see. If
you run everything through htmlentities() but want some things
interpreted, you can always use str_replace() to allow the very specific
tags that you want. There's no need for regular expressions or risking the
<b onclick=""> type of stuff.
But, that's the ncie thing about this list. You get a lot of different
perspectives, answers, etc.
Chris
=====
Chris Shiflett - http://shiflett.org/
PHP Security Handbook
Coming mid-2004
HTTP Developer's Handbook
http://httphandbook.org/
RAMP Training Courses
http://www.nyphp.org/ramp