Re: [PEPr] Comment on HTML::HTML_Safe

From: Date: Sun, 30 Jan 2005 18:23:47 +0000
Subject: Re: [PEPr] Comment on HTML::HTML_Safe
References: 1 2 3 4  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-35809@lists.php.net to get a copy of this message
> I only took a quick look to your code and this thread, however I'm > not sure that the black list basis is a good idea. You know what is > safe, you do not know what is not or will not be (especially what > will not be ;). So maybe allows both black and white modes? Maybe whitelist mode is target for 2.0 release. Blacklist mode has advantages and disadvantages. Main disadvantage is that you described: there's possibility of XSS unknown to me & HTML_Safe. Main advantage is -- most HTML constructions do not breaks by HTML_Safe and user have more freedom. There's some classes of systems which needs such freedom for users: * blogs and blog hostings * wiki with ability of inserting html * CMS with many user levels * Intranet systems For example, Livejournal.com uses blacklisting in their cleanhtml.pl. Of course, there could be systems which needs more security than freedom, may be webmail is example. -- Roman

« previous php.pear.dev (#35809) next »