Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8063325
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 5, 20262026-06-05T10:59:37+00:00 2026-06-05T10:59:37+00:00

I may be thinking too much on this, but let’s say I have a

  • 0

I may be thinking too much on this, but let’s say I have a Website field on database. I’ve used strip_tags to strip all HTML tags. But if the user inputs this

javascript:alert(‘test’)

It will get passed since it’s a string. But then, the HTML will generate

<a href="<?php echo prep_url($website);?>">Website</a> //the code in view file
<a href="javascript:alert('test')">Website</a> //bad

and the Javascript will execute if clicked. Notice too the prep_url doesn’t work.

Any suggestion? I’ve looked at HTMLPurifier, but it is quite big on size and I don’t really want to do some major change.

Thanks

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-05T10:59:38+00:00Added an answer on June 5, 2026 at 10:59 am

    You shouldn’t use strip_tags if you expect a url, you should validate the URL and probably urlencode it. Here’s one way with filter_var:

    $url = "javascript:alert('test')";
    var_dump(filter_var($url, FILTER_VALIDATE_URL));
    // bool(false)
    
    $url = "http://stackoverflow.com/questions/10918132";
    var_dump(filter_var($url, FILTER_VALIDATE_URL));
    // string(43) "http://stackoverflow.com/questions/10918132"
    

    So if filter_var($user_input, FILTER_VALIDATE_URL) is FALSE, don’t accept the user input. This should negate the need for CI’s xss_clean() although you may want to run it anyways when you put it in the HTML attribute. You may need to run prep_url on the input before validating if you don’t require the user to enter the http:// part.

    There are many ways to validate a URL, just pick one you like.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

let's say I have a matrix (array) like this example, but much larger: 0
I may be approaching this problem from the wrong angle but what I'm thinking
Okay this may seem too simple of a question but I've wasted enough time
Coming from a C background, I may be getting too anal about this and
What is the EASIEST way to do this. XOR 0x80 may be too obvious
I'm trying to add a constraint to a controller . I may have this
This may be better suited to Server Fault, but it seems more of a
I'm looking for opinions and/or suggestions on this question. On our website we have
Let's say I have a javascript method that takes a little to long to
May be I am getting old, but I can't find it...

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.