note 33277 modified in function.strip-tags by vrana

From: Date: Mon, 22 Dec 2003 16:32:51 +0000
Subject: note 33277 modified in function.strip-tags by vrana
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-62341@lists.php.net to get a copy of this message
To fix the <scr<script></script>ipt> bug, I'm going to use the following function for my upcoming forum project: function realsafehtml($str) { // Don't do anything if there's no difference or if the original string is empty $oldstr = ""; while($str != $oldstr) // Loop until it got no more effect { $oldstr = $str; //nuke script and header tags and anything inbetween $str = preg_replace("'<script[^>]*>.*</script>'siU", "", $str); $str = preg_replace("'<head[^>]*>.*</head>'siU", "", $str); //listed of tags that will not be striped but whose attributes will be $allowed = "br|b|i|p|u|a|center|hr"; //start nuking those suckers. don you just love MS Word's HTML? $str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "", $str); $str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str); } return $str; } It's obviously more expensive than the original function, but also a lot more secure :) I hope this can help someone - didn't test it much yet, though. [ Editor note: use U (ungreedy) pattern modified to not strip inner contents. ] --was-- To fix the <scr<script></script>ipt> bug, I'm going to use the following function for my upcoming forum project: function realsafehtml($str) { // Don't do anything if there's no difference or if the original string is empty $oldstr = ""; while($str != $oldstr) // Loop until it got no more effect { $oldstr = $str; //nuke script and header tags and anything inbetween $str = preg_replace("'<script[^>]*?>.*?</script>'si", "", $str); $str = preg_replace("'<head[^>]*?>.*?</head>'si", "", $str); //listed of tags that will not be striped but whose attributes will be $allowed = "br|b|i|p|u|a|center|hr"; //start nuking those suckers. don you just love MS Word's HTML? $str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "", $str); $str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str); } return $str; } It's obviously more expensive than the original function, but also a lot more secure :) I hope this can help someone - didn't test it much yet, though. http://www.php.net/manual/en/function.strip-tags.php

« previous php.notes (#62341) next »