note 62684 modified in function.preg-replace by bjori

From: Date: Tue, 07 Mar 2006 14:35:53 +0000
Subject: note 62684 modified in function.preg-replace by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-104995@lists.php.net to get a copy of this message
Inspired by the query-string cleaner from greenthumb at 4point-webdesign dot com and istvan dot csiszar at weblab dot hu. This little bit of code cleans up any "style" attributes in your tags, leaving behind only styles that you have specifically allowed. Also conveniently strips out nonsense styles. I've not fully tested it yet so I'm not sure if it'll handle features like url(), but that shouldn't be a difficulty. <?php /* The string would normally be a form-submitted html file or text string */ $string = '<span style="font-family:arial; font-size:20pt; text-decoration:underline; sausage:bueberry;" width="200">Hello there</span> This is some <div style="display:inline;">test text</div>'; /* Array of styles to allow. */ $except = array('font-family', 'text-decoration'); $allow = implode($except, '|'); /* The monster beast regexp. I was up all night trying to figure this one out. */ $regexp = '@([^;"]+)?(?<!'.$allow.'):(?!\/\/(.+?)\/)((.*?)[^;"]+)(;)?@is'; print str_replace('<', '<', $regexp).'<br/><br/>'; $out = preg_replace($regexp, '', $string); /* Now lets get rid of any unwanted empty style attributes */ $out = preg_replace('@[a-z]*=""@is', '', $out); print $out; ?> This should produce the following: <span style="font-family:arial; text-decoration:underline;" width="200">Hello there</span> This is some <div >test text</div> Now, I'm a relative newbie at this so I'm sure there's a better way to do it. There's *always* a better way. --was-- Inspired by the query-string cleaner from greenthumb at 4point-webdesign dot com and istvan dot csiszar at weblab dot hu. This little bit of code cleans up any "style" attributes in your tags, leaving behind only styles that you have specifically allowed. Also conveniently strips out nonsense styles. I've not fully tested it yet so I'm not sure if it'll handle features like url(), but that shouldn't be a difficulty. <?php /* The string would normally be a form-submitted html file or text string */ $string = '<span style="font-family:arial; font-size:20pt; text-decoration:underline; sausage:bueberry;" width="200">Hello there</span> This is some <div style="display:inline;">test text</div>'; /* Array of styles to allow. */ $except = array('font-family', 'text-decoration'); $allow = implode($except, '|'); /* The monster beast regexp. I was up all night trying to figure this one out. */ $regexp = '@([^;"]+)?(?<!'.$allow.'):((.*?)[^;"]+)(;)?@'; print str_replace('<', '&lt', $regexp).'<br/><br/>'; $out = preg_replace($regexp, '', $string); /* Now lets get rid of any unwanted empty style attributes */ $out = preg_replace('@[a-z]*=""@is', '', $out); print $out; ?> This should produce the following: <span style="font-family:arial; text-decoration:underline;" width="200">Hello there</span> This is some <div >test text</div> Now, I'm a relative newbie at this so I'm sure there's a better way to do it. There's *always* a better way. http://php.net/manual/en/function.preg-replace.php

« previous php.notes (#104995) next »