Posted by John Dunlop on 08/19/06 13:13
Ambush Commander:
> HTMLPurifier is a new PHP library that filters HTML so that not only is
> XSS thwarted, but the resulting HTML is standards-compliant!
Do you mean standards compliant, valid or something else? If you mean
standards compliant - assuming that that includes HTML - you would have
to assign meanings to all the ambiguous clauses of the HTML4.01 spec
(strictly speaking, all of them). If you mean valid, you would have to
guess or somehow infer what any invalid markup was intended to mean
before you could sort it.
--
Jock
[Back to original message]
|