in reply to Re: Re: Back to acceptable untainted characters
in thread Back to acceptable untainted characters
Include that in the main page:<b>Signed up:<b> <table><tr><td><tmpl_var data><\/td><\/tr> <\/table>
And just make sure that the HTML::Template object responsible for populating the main page handles that <tmpl_var data> tag. I discuss this technique more at 3Re: HTML::Template - complex sites. Feel free to play with the code i have posted there.<tmpl_include signed_up.tmpl>
Now then, as for security ... if you don't want to allow your users to submit HTML, the easiest hack you can do is:
This will convert all < characters to < which will effectively keep the tag from rendering.my $data = '<html>evil tags!!</html>'; $data =~ s/</</g;
jeffa
L-LL-L--L-LL-L--L-LL-L-- -R--R-RR-R--R-RR-R--R-RR B--B--B--B--B--B--B--B-- H---H---H---H---H---H--- (the triplet paradiddle with high-hat)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
encoding entities (Re: Back to acceptable untainted characters)
by jonadab (Parson) on Sep 09, 2003 at 03:08 UTC |