“Safe” markdown processor for PHP?

后端 未结 3 394
遥遥无期
遥遥无期 2020-12-12 14:13

Is there a PHP implementation of markdown suitable for using in public comments?

Basically it should only allow a subset of the markdown syntax (bold, italic, links,

3条回答
  •  孤街浪徒
    2020-12-12 14:53

    How about running htmlspecialchars on the user entered input, before processing it through markdown? It should escape anything dangerous, but leave everything that markdown understands.

    I'm trying to think of a case where this wouldn't work but can't think of anything off hand.

提交回复
热议问题