Jump to content

Recommended Posts

I have a site which users can write reviews for products. I want to make sure they don't use malicious code in the reviews like <script> and things like that.

 

How would I go about coding this??

 

Just create an array of words to look for and deny the insert??

 

Any help and code is appreciated.

 

Ray

Link to comment
https://forums.phpfreaks.com/topic/87625-solved-check-for-code/
Share on other sites

I'd stop them from using any html code in your input forms, and just allow them to use bbcode and parse it that way (i.e. replacing all with <b> when you're outputting what they've written).

 

I just think it would be a lot safer that way.

Link to comment
https://forums.phpfreaks.com/topic/87625-solved-check-for-code/#findComment-448188
Share on other sites

Bah, my previous post didn't work the way I intended and I didn't check it

 

(i.e. placing all [b] with <b> when you're outputting what they've written).

 

I'm not sure how you could deny all code except < b > etc that's the problem.  Hopefully someone else can (I'm hopeless with regex)

Link to comment
https://forums.phpfreaks.com/topic/87625-solved-check-for-code/#findComment-448199
Share on other sites

strip_tags lets you pass a string of allowable tags and then it will only strip ones you don't want. You could then compare the original post to the stripped one and if they were different you'd know the user had submitted dodgy content. Obviously that won't help with the seven words you cant say on tv....

Link to comment
https://forums.phpfreaks.com/topic/87625-solved-check-for-code/#findComment-448374
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.