note 37562 added to function.strip-tags

From: Date: Wed, 19 Nov 2003 19:45:13 +0000
Subject: note 37562 added to function.strip-tags
Groups: php.notes 
Request: Send a blank email to php-notes+get-60637@lists.php.net to get a copy of this message
This is a slightly altered version of tREXX's code. The difference is that this one simply removes the unwanted attributes (rather than flagging them as forbidden). function removeEvilAttributes($tagSource) { $stripAttrib = "' (style|class)=\"(.*?)\"'i"; $tagSource = stripslashes($tagSource); $tagSource = preg_replace($stripAttrib, '', $tagSource); return $tagSource; } function removeEvilTags($source) { $allowedTags='<a><br><b><h1><h2><h3><h4><i>' . '<img><li><ol><p><strong><table>' . '<tr><td><th><u><ul>'; $source = strip_tags($source, $allowedTags); return preg_replace('/<(.*?)>/ie', "'<'.removeEvilAttributes('\\1').'>'", $source); } $text = '<p style="Normal">Saluton el <a href="#?" class="xsarial">Esperanto-lando</a><img src="my.jpg" alt="Saluton" width=100 height=100></p>'; $text = removeEvilTags($text); var_dump($text); ---- Manual Page -- http://www.php.net/manual/en/function.strip-tags.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37562 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37562&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37562&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#60637) next »