Re: [PEPr] Comment on HTML::HTML_Safe
| From: | Roman Ivanov | Date: | Sun, 30 Jan 2005 13:01:05 +0000 |
| Subject: | Re: [PEPr] Comment on HTML::HTML_Safe | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-35800@lists.php.net to get a copy of this message | ||
> We definately need a package like that. Mayone one thing that might be nice
> is to make the security policy configurable. So that the user gets more
> control over what gets stripped out.
Security policy of HTML_Safe is fully configurable through class properties:
$singleTags, $deleteTags, $deleteTagsContent, $protocolFiltering,
$blackProtocols, $whiteProtocols, $protocolAttributes, $cssKeywords,
$closeParagraph, $tableTags, $listTags, $attributes.
> However stripping out tags with no closing tag is going too far quite
> often I would say.
HTML_Safe don't strip opened tags with no closing tags. It adds
closing tag on proper nesting level.
--
Roman
http://www.npj.ru/kukutz