note 49234 added to function.preg-replace
| From: | Nick at osu1 dot php dot net | Date: | Thu, 20 Jan 2005 23:05:30 +0000 |
| Subject: | note 49234 added to function.preg-replace | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-83702@lists.php.net to get a copy of this message | ||
Here is a more secure version of the link conversion code which hopefully make cross site scripting
attacks more difficult.
<?php
function convert_links($str) {
$replace = <<<EOPHP
'<a href="'.htmlentities('\\1').htmlentities('\\2').//remove
line break
'">'.htmlentities('\\1').htmlentities('\\2').'</a>'
EOPHP;
$str = preg_replace('#(http://)([^\s]*)#e', $replace, $str);
return $str;
}
?>
----
Manual Page -- http://www.php.net/manual/en/function.preg-replace.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+49234
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+49234&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+49234&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+49234&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+49234&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+49234&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+49234&report=yes
Search -- http://master.php.net/manage/user-notes.php