Minimum HTML Screening Requirements

What are the required and sufficient characters when exiting user content before exiting? (in other words: what are the characters that web developers should avoid when displaying text that was previously received from an unreliable anonymous source?)

+3
source share
2 answers

When you repeat the page you need to encode

  • '&' (ampersand) becomes ' &'
  • '' '(double quote) becomes' "'
  • '' '(single quote) becomes' ''
  • '<' (less) becomes ' &lt;'
  • ' > ' () '&gt;'

PHP htmlspecialchars() docs.

, .

.

+5

, < > & " ' .

0

Source: https://habr.com/ru/post/1751177/


All Articles