note 37562 deleted from function.strip-tags by danbrown
| From: | danbrown@php.net | Date: | Sun, 17 May 2009 16:06:08 +0000 |
| Subject: | note 37562 deleted from function.strip-tags by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-154759@lists.php.net to get a copy of this message | ||
Note Submitter: Tony Freeman
----
This is a slightly altered version of tREXX's code. The difference is that this one simply
removes the unwanted attributes (rather than flagging them as forbidden).
function removeEvilAttributes($tagSource)
{
$stripAttrib = "' (style|class)=\"(.*?)\"'i";
$tagSource = stripslashes($tagSource);
$tagSource = preg_replace($stripAttrib, '', $tagSource);
return $tagSource;
}
function removeEvilTags($source)
{
$allowedTags='<a><br><b><h1><h2><h3><h4><i>'
.
'<img><li><ol><p><strong><table>' .
'<tr><td><th><u><ul>';
$source = strip_tags($source, $allowedTags);
return preg_replace('/<(.*?)>/ie',
"'<'.removeEvilAttributes('\\1').'>'", $source);
}
$text = '<p style="Normal">Saluton el <a href="#?"
class="xsarial">Esperanto-lando</a><img src="my.jpg"
alt="Saluton" width=100 height=100></p>';
$text = removeEvilTags($text);
var_dump($text);