This will disable ALL rendering of HTML tags. It also has the side effect of displaying what the user tried to submit. You could also try to strip out the tags, but this is really a fine art. What if you want to allow some tags like <b> and <u> but disable others like <a> and <script>. Your code will need to be sophisticated. Incidentally, this is what the code in Why I like functional programming addresses.$posted_html =~ s/</</g;
jeffa
L-LL-L--L-LL-L--L-LL-L-- -R--R-RR-R--R-RR-R--R-RR B--B--B--B--B--B--B--B-- H---H---H---H---H---H--- (the triplet paradiddle with high-hat)
In reply to (jeffa) Re: Stopping the abuse
by jeffa
in thread Stopping the abuse
by rezoraith
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |