note 27290 added to function.strip-tags

From: Date: Sat, 30 Nov 2002 23:25:38 +0000
Subject: note 27290 added to function.strip-tags
Groups: php.notes 
Request: Send a blank email to php-notes+get-40192@lists.php.net to get a copy of this message
I implemented the suggestion of "rockylou at icubed dot com" above. Here it is: $ALLOWABLE_TAGS = array("b", "i", "u", "p", "blockquote", "ol", "ul", "li"); function my_htmlspecialchars($text) { global $ALLOWABLE_TAGS; static $PATTERNS = array(); static $REPLACEMENTS = array(); if (count($PATTERNS) == 0) { foreach ($ALLOWABLE_TAGS as $tag) { $PATTERNS[] = "/&lt;$tag&gt;/i"; $PATTERNS[] = "/&lt;\/$tag&gt;/i"; $REPLACEMENTS[] = "<$tag>"; $REPLACEMENTS[] = "</$tag>"; } } $result = str_replace(array(">", "<", "\"", "'"), array("&gt;", "&lt;", "&quot;", "&#039;"), $text); $result = preg_replace($PATTERNS, $REPLACEMENTS, $result); return $result; } This very safe, because it is quite limited in what it allows, rather than trying to exclude everything that shouldn't be there. This does not allow for the <a> tag. To allow for the <a> tag, you'll probably want to do something like changing $PATTERNS[] = "/&lt;$tag&gt;/i"; to $PATTERNS[] = "/&lt;$tag.*&gt;/i"; -- http://www.php.net/manual/en/function.strip-tags.php http://master.php.net/manage/user-notes.php?action=edit+27290 http://master.php.net/manage/user-notes.php?action=delete+27290 http://master.php.net/manage/user-notes.php?action=reject+27290

« previous php.notes (#40192) next »