in reply to Re: XSS-Bug in HTML::BBCode
in thread XSS-Bug in HTML::BBCode
You might consider using HTML::StripScripts (I'm the maintainer) as a filter for your output HTML. It'll filter tags, attributes and styles. Instead of returning the HTML directly, you would need to feed it tokens like start and end tags with attributes, content etc, and set the level of filtering that you would like.
Have a look at HTML::StripScripts::Parser and HTML::StripScripts::LibXML for ideas of how to interface with HTML::Stripscripts.
Clint
|
---|
Replies are listed 'Best First'. | |
---|---|
Re: XSS-Bug in HTML::BBCode
by b10m (Vicar) on Aug 14, 2007 at 14:52 UTC | |
by clinton (Priest) on Aug 14, 2007 at 15:00 UTC |
In Section
Seekers of Perl Wisdom