Login or Sign Up
Logging in...
Remember me
Log in
Or
Sign Up
Forgot password or user name?
Log in with
Search in titles only
Search in PHP only
Search
Advanced Search
Forums
BYTES
Product Launch
Updates
Developer Toolkit
Today's Posts
Member List
Calendar
Home
Forum
Topic
PHP
Is it safe to allow HTML code inside PHP?
Collapse
X
Collapse
Posts
Latest Activity
Photos
Page
of
1
Filter
Time
All Time
Today
Last Week
Last Month
Show
All
Discussions only
Photos only
Videos only
Links only
Polls only
Events only
Filtered by:
Clear All
new posts
Previous
template
Next
olddocks
New Member
Join Date:
Nov 2007
Posts:
26
#1
Is it safe to allow HTML code inside PHP?
Dec 6 '07, 01:28 PM
is it safe to allow users using a html text editor? i got open source java script based HTML editor and i am using it to allow people to type their blog and forum?
is it safe?
Markus
Recognized Expert
Expert
Join Date:
Jun 2007
Posts:
6092
#2
Dec 6 '07, 02:56 PM
If you use the proper precautions.
And it's probably safe to assume that because it's an open source editor, there'll be some safety features within it.
Couldn't say without looking at it.
And what does php have to do with it, if you're using javascript?
Comment
Post
Cancel
olddocks
New Member
Join Date:
Nov 2007
Posts:
26
#3
Dec 6 '07, 05:20 PM
thanks markus :)
actually, i am bit worried becuase people can upload HTML files in the editor and PHP script outputting the page. Like..
$text = <html content is stored in database>
and a PHP file like show.php echoing the $text.
Comment
Post
Cancel
Markus
Recognized Expert
Expert
Join Date:
Jun 2007
Posts:
6092
#4
Dec 6 '07, 05:32 PM
Well, if that's what you allow people to do, then there's nothing you can do to stop people.
They will be unable to do such things as mysql injection, though.
Comment
Post
Cancel
Previous
template
Next
Working...
Yes
No
OK
OK
Cancel
👍
👎
☕
Comment