note 15479 deleted from function.strip-tags by vrana
| From: | vrana@php.net | Date: | Mon, 22 Dec 2003 15:31:12 +0000 |
| Subject: | note 15479 deleted from function.strip-tags by vrana | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-62319@lists.php.net to get a copy of this message | ||
Note Submitter: maxy_v@mail.ru
----
Also if you need to remove attributes from allowed tags: (that's just a modification of
function that toni@dse.nl sent here)
function safeHTML($html, $tags = "b|br|i|u|ul|ol|li") {
// removes all tags that are considered unsafe
// why should there be a null character
$html = preg_replace('/\0/', '', $html);
// convert the ampersants to null characters
$html = preg_replace('/\&/', '\0', $html);
// convert the sharp brackets to there html code and excape special charachters such as "
$html=htmlspecialchars($html);
// restore the tags that are concidered safe
if ($tags) {
//this statement not only escapes "unsafe" tags, but also removes all attributes from SAFE
tags
$html = preg_replace("/<($tags).*?>/i", '<\1>', $html);
$html = preg_replace("/<\\/($tags)>/i", '</\1>', $html);
}
/*if (count($tags_with_attrs)){
}*/
// restore the ampersants
$html = preg_replace('/\0/', '&', $html);
return($html);
} // safeHTML
Tryed to make a function that let to leave desired attributes in allowable tags, and removes all the
others - but couldn't figure out how to do that using REGEXPs. Looks like will have to use XML
parser etc :-(