HTML Purifier - what to purify?

前端 未结 4 1351
遥遥无期
遥遥无期 2021-01-11 15:11

I am using HTML Purifier to protect my application from XSS attacks. Currently I am purifying content from WYSIWYG editors because that is the only place where users are all

4条回答
  •  南笙
    南笙 (楼主)
    2021-01-11 15:54

    You should Purify anything that will ever possibly be displayed on a page. Because with XSS attacks, hackers put in

提交回复
热议问题