[PEPr] Comment on HTML::HTML_Safe
| From: | Lukas Smith | Date: | Sat, 29 Jan 2005 18:09:30 +0000 |
| Subject: | [PEPr] Comment on HTML::HTML_Safe | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-35788@lists.php.net to get a copy of this message | ||
Lukas Smith (http://pear.php.net/user/lsmith) has commented on the proposal for HTML::HTML_Safe.
Comment:
We definately need a package like that. Mayone one thing that might be nice
is to make the security policy configurable. So that the user gets more
control over what gets stripped out. Then again there might be little
sense in doing that since one holes is enough ..
However stripping out tags with no closing tag is going too far quite
often I would say. Since we are talking about user probided input here
mostly, it needs to be nice to the user too. Maybe an optional solution
should therefore be to automatically add a " /" at the end of the opening
tag.
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=199
--
Sent by PEPr, the automatic proposal system at http://pear.php.net