note 27290 added to function.strip-tags
| From: | etymxris at yahoo dot com | Date: | Sat, 30 Nov 2002 23:25:38 +0000 |
| Subject: | note 27290 added to function.strip-tags | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-40192@lists.php.net to get a copy of this message | ||
I implemented the suggestion of "rockylou at icubed dot com" above.
Here it is:
$ALLOWABLE_TAGS = array("b", "i", "u", "p",
"blockquote", "ol", "ul", "li");
function my_htmlspecialchars($text) {
global $ALLOWABLE_TAGS;
static $PATTERNS = array();
static $REPLACEMENTS = array();
if (count($PATTERNS) == 0) {
foreach ($ALLOWABLE_TAGS as $tag) {
$PATTERNS[] = "/<$tag>/i";
$PATTERNS[] = "/<\/$tag>/i";
$REPLACEMENTS[] = "<$tag>";
$REPLACEMENTS[] = "</$tag>";
}
}
$result = str_replace(array(">", "<", "\"",
"'"),
array(">", "<", """,
"'"),
$text);
$result = preg_replace($PATTERNS, $REPLACEMENTS, $result);
return $result;
}
This very safe, because it is quite limited in what it allows, rather than trying to exclude
everything that shouldn't be there. This does not allow for the <a> tag. To allow for the
<a> tag, you'll probably want to do something like changing
$PATTERNS[] = "/<$tag>/i";
to
$PATTERNS[] = "/<$tag.*>/i";
--
http://www.php.net/manual/en/function.strip-tags.php
http://master.php.net/manage/user-notes.php?action=edit+27290
http://master.php.net/manage/user-notes.php?action=delete+27290
http://master.php.net/manage/user-notes.php?action=reject+27290