Re: [PEPr] Comment on HTML::HTML_Safe

From: Date: Sun, 30 Jan 2005 13:01:05 +0000
Subject: Re: [PEPr] Comment on HTML::HTML_Safe
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-35800@lists.php.net to get a copy of this message
> We definately need a package like that. Mayone one thing that might be nice > is to make the security policy configurable. So that the user gets more > control over what gets stripped out. Security policy of HTML_Safe is fully configurable through class properties: $singleTags, $deleteTags, $deleteTagsContent, $protocolFiltering, $blackProtocols, $whiteProtocols, $protocolAttributes, $cssKeywords, $closeParagraph, $tableTags, $listTags, $attributes. > However stripping out tags with no closing tag is going too far quite > often I would say. HTML_Safe don't strip opened tags with no closing tags. It adds closing tag on proper nesting level. -- Roman http://www.npj.ru/kukutz

« previous php.pear.dev (#35800) next »