Re: [PEPr] Comment on HTML::HTML_Safe
| From: | Jamie Alessio | Date: | Mon, 31 Jan 2005 17:05:04 +0000 |
| Subject: | Re: [PEPr] Comment on HTML::HTML_Safe | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-35826@lists.php.net to get a copy of this message | ||
For reference, there is a similar project written in PHP called htmlfilter available at http://linux.duke.edu/projects/mini/htmlfilter/
It provides both blacklist and whitelist based filtering, will close open tags, strips out specific attributes in tags, adds attribute to tags. It was originally written as a tool for squirrelmail (www.squirrelmail.org) but now stands on its own. One downside is that the configuration is complex and can be confusing but that buys you a lot of power since you can specify html stripping rules using perl regular expressions.
- Jamie
Daniel Convissor (http://pear.php.net/user/danielc) has commented on the proposal for HTML::HTML_Safe.
Comment:
Is there any relation between your package and SafeHTML?
http://freshmeat.net/projects/safehtml/
Does your package deal with people trying to obfuscate their attacks by
using HTML entities (both ordinal and hex)? This was an issue in SafeHTML
which they apparently addressed in release 1.2.1.
The layout of arrays could use some neatening up, including
alphabetizing:
$array = array(
'another',
'value',
);
Some other pedantic comments:
* use single quotes instead of double quotes around strings when
possible.
* put spaces between concatenated elements (eg "/" . $css . "/i") and
assignment operators (eg $this->_xhtml .= "<" . $name;).
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=199