note 36574 added to function.strip-tags

From: Date: Wed, 15 Oct 2003 10:15:54 +0000
Subject: note 36574 added to function.strip-tags
Groups: php.notes 
Request: Send a blank email to php-notes+get-58616@lists.php.net to get a copy of this message
Here's a quite fast solution to remove unwanted tags AND also unwanted attributes within the allowed tags: <?php /** * Allow these tags */ $allowedTags = '<h1><b><i><a><ul><li><pre><hr><blockquote><img>'; /** * Disallow these attributes/prefix within a tag */ $stripAttrib = 'javascript:|onclick|ondblclick|onmousedown|onmouseup|onmouseover|'. 'onmousemove|onmouseout|onkeypress|onkeydown|onkeyup'; /** * @return string * @param string * @desc Strip forbidden tags and delegate tag-source check to removeEvilAttributes() */ function removeEvilTags($source) { global $allowedTags; $source = strip_tags($source, $allowedTags); return preg_replace('/<(.*?)>/ie', "'<'.removeEvilAttributes('\\1').'>'", $source); } /** * @return string * @param string * @desc Strip forbidden attributes from a tag */ function removeEvilAttributes($tagSource) { global $stripAttrib; return stripslashes(preg_replace("/$stripAttrib/i", 'forbidden', $tagSource)); } // Will output: <a href="forbiddenalert(1);" target="_blank" forbidden =" alert(1)">test</a> echo removeEvilTags('<a href="javascript:alert(1);" target="_blank" onMouseOver = "alert(1)">test</a>'); ?> ---- Manual Page -- http://www.php.net/manual/en/function.strip-tags.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+36574 Delete -- http://master.php.net/manage/user-notes.php?action=delete+36574&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+36574&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#58616) next »