note 15479 deleted from function.strip-tags by vrana

From: Date: Mon, 22 Dec 2003 15:31:12 +0000
Subject: note 15479 deleted from function.strip-tags by vrana
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-62319@lists.php.net to get a copy of this message
Note Submitter: maxy_v@mail.ru ---- Also if you need to remove attributes from allowed tags: (that's just a modification of function that toni@dse.nl sent here) function safeHTML($html, $tags = "b|br|i|u|ul|ol|li") { // removes all tags that are considered unsafe // why should there be a null character $html = preg_replace('/\0/', '', $html); // convert the ampersants to null characters $html = preg_replace('/\&/', '\0', $html); // convert the sharp brackets to there html code and excape special charachters such as " $html=htmlspecialchars($html); // restore the tags that are concidered safe if ($tags) { //this statement not only escapes "unsafe" tags, but also removes all attributes from SAFE tags $html = preg_replace("/&lt;($tags).*?&gt;/i", '<\1>', $html); $html = preg_replace("/&lt;\\/($tags)&gt;/i", '</\1>', $html); } /*if (count($tags_with_attrs)){ }*/ // restore the ampersants $html = preg_replace('/\0/', '&', $html); return($html); } // safeHTML Tryed to make a function that let to leave desired attributes in allowable tags, and removes all the others - but couldn't figure out how to do that using REGEXPs. Looks like will have to use XML parser etc :-(

« previous php.notes (#62319) next »