Seriously, the right way to handle security is to explicitly list what is allowed and filter out all else. Add to what is allowed as the need/desire comes up.
EDIT
I should explain the isotope comment.
At this moment there is an image snuck onto a novice's page through the table tag. Personally I think it is very respectfully done, but the point is that until you really stop and think about a construct, you have no idea what someone may come up with...
In reply to RE: HTML tags to be filtered out
by tilly
in thread HTML tags to be filtered out
by vroom
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |