note 36574 added to function.strip-tags
| From: | tREXX at rn2 dot php dot net | Date: | Wed, 15 Oct 2003 10:15:54 +0000 |
| Subject: | note 36574 added to function.strip-tags | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-58616@lists.php.net to get a copy of this message | ||
Here's a quite fast solution to remove unwanted tags AND also unwanted attributes within the
allowed tags:
<?php
/**
* Allow these tags
*/
$allowedTags =
'<h1><b><i><a><ul><li><pre><hr><blockquote><img>';
/**
* Disallow these attributes/prefix within a tag
*/
$stripAttrib = 'javascript:|onclick|ondblclick|onmousedown|onmouseup|onmouseover|'.
'onmousemove|onmouseout|onkeypress|onkeydown|onkeyup';
/**
* @return string
* @param string
* @desc Strip forbidden tags and delegate tag-source check to removeEvilAttributes()
*/
function removeEvilTags($source)
{
global $allowedTags;
$source = strip_tags($source, $allowedTags);
return preg_replace('/<(.*?)>/ie',
"'<'.removeEvilAttributes('\\1').'>'", $source);
}
/**
* @return string
* @param string
* @desc Strip forbidden attributes from a tag
*/
function removeEvilAttributes($tagSource)
{
global $stripAttrib;
return stripslashes(preg_replace("/$stripAttrib/i", 'forbidden',
$tagSource));
}
// Will output: <a href="forbiddenalert(1);" target="_blank" forbidden
=" alert(1)">test</a>
echo removeEvilTags('<a href="javascript:alert(1);" target="_blank"
onMouseOver = "alert(1)">test</a>');
?>
----
Manual Page -- http://www.php.net/manual/en/function.strip-tags.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+36574
Delete -- http://master.php.net/manage/user-notes.php?action=delete+36574&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+36574&report=yes
Search -- http://master.php.net/manage/user-notes.php