note 33277 modified in function.strip-tags by vrana
| From: | vrana@php.net | Date: | Mon, 22 Dec 2003 16:41:00 +0000 |
| Subject: | note 33277 modified in function.strip-tags by vrana | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-62345@lists.php.net to get a copy of this message | ||
To fix the <scr<script></script>ipt> bug, I'm going to use the following
function for my upcoming forum project:
function realsafehtml($str) {
// Don't do anything if there's no difference or if the original string is empty
$oldstr = "";
while($str != $oldstr) // Loop until it got no more effect
{
$oldstr = $str;
//nuke script and header tags and anything inbetween
$str = preg_replace("'<script[^>]*>.*</script>'siU",
"", $str);
$str = preg_replace("'<head[^>]*>.*</head>'siU",
"", $str);
//listed of tags that will not be striped but whose attributes will be
$allowed = "br|b|i|p|u|a|center|hr";
//start nuking those suckers. don you just love MS Word's HTML?
$str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "",
$str);
$str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str);
}
return $str;
}
It's obviously more expensive than the original function, but also a lot more secure :) I hope
this can help someone - didn't test it much yet, though.
--was--
To fix the <scr<script></script>ipt> bug, I'm going to use the following
function for my upcoming forum project:
function realsafehtml($str) {
// Don't do anything if there's no difference or if the original string is empty
$oldstr = "";
while($str != $oldstr) // Loop until it got no more effect
{
$oldstr = $str;
//nuke script and header tags and anything inbetween
$str = preg_replace("'<script[^>]*>.*</script>'siU",
"", $str);
$str = preg_replace("'<head[^>]*>.*</head>'siU",
"", $str);
//listed of tags that will not be striped but whose attributes will be
$allowed = "br|b|i|p|u|a|center|hr";
//start nuking those suckers. don you just love MS Word's HTML?
$str = preg_replace("/<((?!\/?($allowed)\b)[^>]*>)/xis", "",
$str);
$str = preg_replace("/<($allowed).*?>/i", "<\\1>", $str);
}
return $str;
}
It's obviously more expensive than the original function, but also a lot more secure :) I hope
this can help someone - didn't test it much yet, though.
[ Editor note: use U (ungreedy) pattern modified to not strip inner contents. ]
http://www.php.net/manual/en/function.strip-tags.php