Re: [PEPr] Comment on HTML::HTML_Safe

From: Date: Sun, 30 Jan 2005 13:19:56 +0000
Subject: Re: [PEPr] Comment on HTML::HTML_Safe
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-35799@lists.php.net to get a copy of this message
> Are you familliar with PHP's strip_tags function? Of course, I'm familiar with it. HTML_safe has those differences with strip_tags(): 1. strip_tags works on white-list basis, deleting all tags except allowed. HTML_Safe works on black-list basis, deleting only dangerous content. 2. strip_tags can only strip tags. HTML_safe strips down all active content, including tags, attributes and values of atrributes. 3. strip_tags is not intended to fight XSS. HTML_Safe has primary goal to prevent any XSS attack. 4. strip_tags does not try to produce XHTML compliant code. It is do not close unclosed tags. And so on. > There seems to be some overlap, though you provide more thorough sanitization. Here's analogue: there seems to be some overlap between Mail PEAR class and mail() PHP function. > How about having > the description explain the differences between your package and the > function? This will avoid more people asking this question. Have I provided enough information on this topic? > Please explain the benefit of this package over using Over using strip_tags? > Please check out the phpDocumentor manual and the Sample File in the PEAR > Coding Standards. I fixed some issues. Is it OK now? -- Roman http://www.npj.ru/kukutz

« previous php.pear.dev (#35799) next »