Re: [PEPr] Comment on HTML::HTML_Safe
| From: | Roman Ivanov | Date: | Sun, 30 Jan 2005 13:19:56 +0000 |
| Subject: | Re: [PEPr] Comment on HTML::HTML_Safe | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-35799@lists.php.net to get a copy of this message | ||
> Are you familliar with PHP's strip_tags function?
Of course, I'm familiar with it.
HTML_safe has those differences with strip_tags():
1. strip_tags works on white-list basis, deleting all tags except
allowed. HTML_Safe works on black-list basis, deleting only dangerous
content.
2. strip_tags can only strip tags. HTML_safe strips down all active
content, including tags, attributes and values of atrributes.
3. strip_tags is not intended to fight XSS. HTML_Safe has primary goal
to prevent any XSS attack.
4. strip_tags does not try to produce XHTML compliant code. It is do
not close unclosed tags.
And so on.
> There seems to be some overlap, though you provide more thorough sanitization.
Here's analogue: there seems to be some overlap between Mail PEAR
class and mail() PHP function.
> How about having
> the description explain the differences between your package and the
> function? This will avoid more people asking this question.
Have I provided enough information on this topic?
> Please explain the benefit of this package over using
Over using strip_tags?
> Please check out the phpDocumentor manual and the Sample File in the PEAR
> Coding Standards.
I fixed some issues. Is it OK now?
--
Roman
http://www.npj.ru/kukutz