note 59960 deleted from function.preg-replace by felipe
| From: | felipe@php.net | Date: | Mon, 10 Dec 2007 02:07:39 +0000 |
| Subject: | note 59960 deleted from function.preg-replace by felipe | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-133089@lists.php.net to get a copy of this message | ||
Note Submitter: istvan dot csiszar at weblab dot hu
----
This is an addition to the previously sent removeEvilTags function. If you don't want to remove
the style tag entirely, just certain style attributes within that, then you might find this piece of
code useful:
<?php
function removeEvilStyles($tagSource)
{
// this will leave everything else, but:
$evilStyles = array('font', 'font-family', 'font-face',
'font-size', 'font-size-adjust', 'font-stretch',
'font-variant');
$find = array();
$replace = array();
foreach ($evilStyles as $v)
{
$find[] = "/$v:.*?;/";
$replace[] = '';
}
return preg_replace($find, $replace, $tagSource);
}
function removeEvilTags($source)
{
$allowedTags =
'<h1><h2><h3><h4><h5><a><img><label>'.
'<p><br><span><sup><sub><ul><li><ol>'.
'<table><tr><td><th><tbody><div><hr><em><b><i>';
$source = strip_tags(stripslashes($source), $allowedTags);
return trim(preg_replace('/<(.*?)>/ie',
"'<'.removeEvilStyles('\\1').'>'", $source));
}
?>