duanhan4763 2011-07-14 02:54
浏览 27
已采纳

通过删除所有JavaScript代码和事件使字符串安全

I want to remove all javascript codes from a string that contains html code.

For example these are some unwanted javascript codes that may cause problems on your website:

<div onmouseover='window.location = "http://To-Undesirable-Location"'></div>

or

<img onload='window.location = "http://To-Undesirable-Location"'></img>

or

<script language="javascript> ...unwanted code... </script>

Since hackers can use this js functions to redirect your page to some unwanted pages I wonder why there are not some good source to make this type of content safe... On any website there are usually a simple WYSIWYG editor that users can put their html content inside it.

Thanks

  • 写回答

1条回答 默认 最新

  • douzou8074 2011-07-14 02:59
    关注

    I've heard good things on Stack Overflow about HTML Purifier.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 ETLCloud 处理json多层级问题
  • ¥15 matlab中使用gurobi时报错
  • ¥15 这个主板怎么能扩出一两个sata口
  • ¥15 不是,这到底错哪儿了😭
  • ¥15 2020长安杯与连接网探
  • ¥15 关于#matlab#的问题:在模糊控制器中选出线路信息,在simulink中根据线路信息生成速度时间目标曲线(初速度为20m/s,15秒后减为0的速度时间图像)我想问线路信息是什么
  • ¥15 banner广告展示设置多少时间不怎么会消耗用户价值
  • ¥15 可见光定位matlab仿真
  • ¥15 arduino 四自由度机械臂
  • ¥15 wordpress 产品图片 GIF 没法显示