duanhan4763 2011-07-14 02:54
浏览 27
已采纳

通过删除所有JavaScript代码和事件使字符串安全

I want to remove all javascript codes from a string that contains html code.

For example these are some unwanted javascript codes that may cause problems on your website:

<div onmouseover='window.location = "http://To-Undesirable-Location"'></div>

or

<img onload='window.location = "http://To-Undesirable-Location"'></img>

or

<script language="javascript> ...unwanted code... </script>

Since hackers can use this js functions to redirect your page to some unwanted pages I wonder why there are not some good source to make this type of content safe... On any website there are usually a simple WYSIWYG editor that users can put their html content inside it.

Thanks

  • 写回答

1条回答 默认 最新

  • douzou8074 2011-07-14 02:59
    关注

    I've heard good things on Stack Overflow about HTML Purifier.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 stata安慰剂检验作图但是真实值不出现在图上
  • ¥15 c程序不知道为什么得不到结果
  • ¥40 复杂的限制性的商函数处理
  • ¥15 程序不包含适用于入口点的静态Main方法
  • ¥15 素材场景中光线烘焙后灯光失效
  • ¥15 请教一下各位,为什么我这个没有实现模拟点击
  • ¥15 执行 virtuoso 命令后,界面没有,cadence 启动不起来
  • ¥50 comfyui下连接animatediff节点生成视频质量非常差的原因
  • ¥20 有关区间dp的问题求解
  • ¥15 多电路系统共用电源的串扰问题