note 36898 modified in function.strip-tags by danbrown
| From: | danbrown@php.net | Date: | Sun, 17 May 2009 16:07:22 +0000 |
| Subject: | note 36898 modified in function.strip-tags by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-154760@lists.php.net to get a copy of this message | ||
it seems we're all overlooking a few things:
1) if we replace "</ta</tableble>" by removing </table, we're not better
off. try using a char-by-char comparison, and replaceing stuff with *s, because then this ex would
become "</ta******ble>", which is not problemmatic; also, with a char by char
approach, you can skip whitespace, and kill stuff like "< table>"... just make sure
<&bkspTable> doesn't work...
2) no browser treats { as <.[as far as i know]
3) because of statement 2, we can do:
<?php
$remove=array("<?","<","?>",">");
$change=array("{[pre]}","{[","{/pre}","]}");
$repairSeek = array("{[pre]}",
"</pre>","{[b]}","{[/b]}","{[br]}");
// and so forth...
$repairChange("<pre>","</pre>","<b>","<b>","<br>");
// and so forth...
$maltags=array("{[","]}");
$nontags=array("{","}");
$unclean=...;//get variable from somewhere...
$unclean=str_replace($remove,$change,$unclean);
$unclean=str_replace($repairSeek, $repairChange, $unclean);
$clean=str_replace($maltags, $nontags, $unclean);
////end example....
?>
4) we can further improve the above by using explode(for our ease):
<?php
function purifyText($unclean, $fixme)
{
$remove=array();
$remove=explode("\n",$fixit['remove']);
//... and so forth for each of the above arrays...
// or you could just pass the arrays..., or a giant string
//put above here...
return $clean
}//done
?>
--was--
it seems we're all overlooking a few things:
1) if we replace "</ta</tableble>" by removing </table, we're not better
off. try using a char-by-char comparison, and replaceing stuff with *s, because then this ex would
become "</ta******ble>", which is not problemmatic; also, with a char by char
approach, you can skip whitespace, and kill stuff like "< table>"... just make sure
<&bkspTable> doesn't work...
2) no browser treats { as <.[as far as i know]
3) because of statement 2, we can do:
$remove=array("<?","<","?>",">");
$change=array("{[pre]}","{[","{/pre}","]}");
$repairSeek = array("{[pre]}",
"</pre>","{[b]}","{[/b]}","{[br]}");
// and so forth...
$repairChange("<pre>","</pre>","<b>","<b>","<br>");
// and so forth...
$maltags=array("{[","]}");
$nontags=array("{","}");
$unclean=...;//get variable from somewhere...
$unclean=str_replace($remove,$change,$unclean);
$unclean=str_replace($repairSeek, $repairChange, $unclean);
$clean=str_replace($maltags, $nontags, $unclean);
////end example....
4) we can further improve the above by using explode(for our ease):
function purifyText($unclean, $fixme)
{
$remove=array();
$remove=explode("\n",$fixit['remove']);
//... and so forth for each of the above arrays...
// or you could just pass the arrays..., or a giant string
//put above here...
return $clean
}//done
http://php.net/manual/en/function.strip-tags.php