Re: [PEPr] Comment on HTML::HTML_Safe

From: Date: Mon, 31 Jan 2005 17:05:04 +0000
Subject: Re: [PEPr] Comment on HTML::HTML_Safe
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-35826@lists.php.net to get a copy of this message
For reference, there is a similar project written in PHP called htmlfilter available at http://linux.duke.edu/projects/mini/htmlfilter/ It provides both blacklist and whitelist based filtering, will close open tags, strips out specific attributes in tags, adds attribute to tags. It was originally written as a tool for squirrelmail (www.squirrelmail.org) but now stands on its own. One downside is that the configuration is complex and can be confusing but that buys you a lot of power since you can specify html stripping rules using perl regular expressions. - Jamie
Daniel Convissor (http://pear.php.net/user/danielc) has commented on the proposal for HTML::HTML_Safe. Comment: Is there any relation between your package and SafeHTML? http://freshmeat.net/projects/safehtml/ Does your package deal with people trying to obfuscate their attacks by using HTML entities (both ordinal and hex)? This was an issue in SafeHTML which they apparently addressed in release 1.2.1. The layout of arrays could use some neatening up, including alphabetizing: $array = array(
    'another',
    'value',
); Some other pedantic comments: * use single quotes instead of double quotes around strings when possible. * put spaces between concatenated elements (eg "/" . $css . "/i") and assignment operators (eg $this->_xhtml .= "<" . $name;). Proposal information: http://pear.php.net/pepr/pepr-proposal-show.php?id=199


« previous php.pear.dev (#35826) next »