PEAK XOOPS - Re: Re: HTMLPurifier in englishin japanese

Re: Re: HTMLPurifier

Target News
Subject HTMLPurifier
Summary WYSIWYGエディタを有効にするなら、基本的にHTML表示許可でデータを受け取るしかないのですが、そうするとScriptInsertionが避けられません。HTMLを再構築してくれるライブラリさえあればなあ、と思っていたら、kentaulsさんが教えてくれました。HTMLPurifierhttp://htmlp...

List posts in the topic

none Re: Re: HTMLPurifier

msg# 1.2
depth:
1
Previous post - Next post | Parent - Children.1 | Posted on 2007/9/25 16:19
kentauls  上等兵   Posts: 29
Hi GIJOE,

Yes, I can imagine.
I didn't think that you took wrong version of HTML Purifier .

Here I quote the lines written in the HTML Purifier archives to let many people know the concept.

Quote:
WYSIWYG - What You See Is What You Get
HTML Purifier: A Pretty Good Fit for TinyMCE and FCKeditor

Javascript-based WYSIWYG editors, simply stated, are quite amazing. But I've
always been wary about using them due to security issues: they handle the
client-side magic, but once you've been served a piping hot load of unfiltered
HTML, what should be done then? In some situations, you can serve it uncleaned,
since you only offer these facilities to trusted(?) authors.

Unfortunantely, for blog comments and anonymous input, BBCode, Textile and
other markup languages still reign supreme. Put simply: filtering HTML is
hard work, and these WYSIWYG authors don't offer anything to alleviate that
trouble. Therein lies the solution:

HTML Purifier is perfect for filtering pure-HTML input from WYSIWYG editors.

Enough said.

I know nothing perfect in the world, but hope it can be enough appropriate for use of FCKeditor on d3forum not for anonymous but members!!
Votes:1 Average:10.00

Posts tree

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!