Strip out ALL javascript from HTML source

On 4/4/07, Phlip [email protected] wrote:

either a Wiki markup (or YAML), or permit a subset of HTML. To
transclude Object tags, invent a new tag called


Phlip

If it were a public blog then I would say you would be right and I
wouldn’t
be so worried but this app is not for a blog.

I’ve been considering the suggestion of creating custom

Cheers

On 4/4/07, [email protected] [email protected] wrote:

We http://www.jobscore.com use SafeHtml <http://pixel-apes.com/
safehtml/> it’s really good about leaving the tags alone but removing
potentially dangerous XSS type stuff.

It’s PHP, but I wrapped it in a class that shells out to the php
interpreter.

Thanx for the link. At my first quick glance it looks like the
WhiteList
plugin will do these things as well with a few tweaks.

I will have a bit better look at it when I get a chance