note 28662 deleted from function.strip-tags by vrana
| From: | vrana@php.net | Date: | Mon, 22 Dec 2003 16:24:08 +0000 |
| Subject: | note 28662 deleted from function.strip-tags by vrana | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-62335@lists.php.net to get a copy of this message | ||
Note Submitter: xing@mac.com
----
This is safehtml() function that is based on comments posted by past users plush a bit of my own.
What it does is very safely strip out any javascript code, unwanted html tags, and html attributes.
Have fun! regex kind of sucks and I'm posting this to save you guys headaches of getting it
working right yourself.
function safehtml($str) {
//nuke script and header tags and anything inbetween
$str = preg_replace("'<script[^>]*?>.*?</script>'si",
"", $str);
$str = preg_replace("'<head[^>]*?>.*?</head>'si",
"", $str);
//listed of tags that will not be striped but whose attributes will be
$allowed = "br|b|i|p|u|a|block|pre|center|hr";
//start nuking those suckers. don you just love MS Word's HTML?
$str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "",
$str);
$str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str);
return $str;
}