note 40222 rejected from function.strip-tags by nlopess
| From: | nlopess@php.net | Date: | Mon, 01 Mar 2004 14:20:52 +0000 |
| Subject: | note 40222 rejected from function.strip-tags by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-66043@lists.php.net to get a copy of this message | ||
Note Submitter: donnelly@snowcrest.com
----
Warning: I found an anomaly (potential bug) in strip_tags(). And where there is smoke there is
usually fire, so don't trust this function 100%.
In the following html example:
<tr><td colspan=2>"19880101" AND date_purch <= "20030202" AND
order_stat =</td></tr>
strip_tags() returned:
"19880101" AND date_purch '
(I added the trailing single quote here to show the trailing space)
strip_tags() apparently didn't like the "<=" and thought it was the beginning of
an html tag and stripped the rest of the line. (?)
My safety work-around was this:
$text = str_replace (" <= ", " <eqcond; ", $text); // bug in
strip_tags function requires
$text = str_replace (" >= ", " >eqcond; ", $text); // protection of
angle bracket
$text = str_replace (" < ", " <cond; ", $text); // conditional
comparison operators --
$text = str_replace (" > ", " >cond; ", $text); // assumes space
on either side
$text = str_replace (" <> ", " &neqcond; ", $text);
$text = strip_tags ($text); // strip out all HTML tags (NOTE bug problem above)
$text = str_replace ("<eqcond;", "<=", $text); // correct protected
operators... (see above)
$text = str_replace (">eqcond;", ">=", $text);
$text = str_replace ("<cond;", "<", $text);
$text = str_replace (">cond;", ">", $text);
$text = str_replace ("&neqcond;", "<>", $text);