note 28662 added to function.strip-tags

From: Date: Mon, 20 Jan 2003 06:33:44 +0000
Subject: note 28662 added to function.strip-tags
Groups: php.notes 
Request: Send a blank email to php-notes+get-42410@lists.php.net to get a copy of this message
This is safehtml() function that is based on comments posted by past users plush a bit of my own. What it does is very safely strip out any javascript code, unwanted html tags, and html attributes. Have fun! regex kind of sucks and I'm posting this to save you guys headaches of getting it working right yourself. function safehtml($str) { //nuke script and header tags and anything inbetween $str = preg_replace("'<script[^>]*?>.*?</script>'si", "", $str); $str = preg_replace("'<head[^>]*?>.*?</head>'si", "", $str); //listed of tags that will not be striped but whose attributes will be $allowed = "br|b|i|p|u|a|block|pre|center|hr"; //start nuking those suckers. don you just love MS Word's HTML? $str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "", $str); $str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str); return $str; } -- http://www.php.net/manual/en/function.strip-tags.php http://master.php.net/manage/user-notes.php?action=edit+28662 http://master.php.net/manage/user-notes.php?action=delete+28662 http://master.php.net/manage/user-notes.php?action=reject+28662

« previous php.notes (#42410) next »