You are here: Re[5]: [PHP] Re: Security, Late Nights and Overall Paranoia « PHP « IT news, forums, messages
Re[5]: [PHP] Re: Security, Late Nights and Overall Paranoia

Posted by Richard Davey on 07/09/05 21:22

To follow-up my own post... which is sad I know, but hey...

Saturday, July 9, 2005, 7:08:37 PM, I wrote:

RD> The difference is the extra hoops your reg exps will have to jump
RD> through, and have to jump through perfectly. You will have to disallow
RD> all <'s and >'s, but do allow them for <i>, <b>, etc etc. Then check

I forgot to add that BB style codes come into real use for things a
little more advanced than <i>. For example [red] to colour some text.
If you wish to allow this in HTML format you can either invalidate
your XHTML and allow <font> tags, otherwise allow spans with embedded
CSS?! Even if you do allow <font> you're then parsing for color="" and
nothing else, with potential variable width colours. After a short
while you'll find yourself having to write an HTML validator tool (and
I'm sorry but I have *never* seen one that worked flawlessly yet).

Best regards,

Richard Davey
--
http://www.launchcode.co.uk - PHP Development Services
"I do not fear computers. I fear the lack of them." - Isaac Asimov

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация