How can I allow my user to insert HTML code, without risks? (not only technical risks)

后端 未结 10 827
一生所求
一生所求 2020-12-09 05:41

I developed a web application, that permits my users to manage some aspects of a web site dynamically (yes, some kind of cms) in LAMP environment (debian, apache, php, mysql

10条回答
  •  不思量自难忘°
    2020-12-09 06:19

    If you are using php, an excellent solution is to use HTMLPurifier. It has many options to filter out bad stuff, and as a side effect, guarantees well formed html output. I use it to view spam which can be a hostile environment.

提交回复
热议问题