[wp-trac] Re: [WordPress Trac] #4409: KSES removes text after a non-tag less than sign

WordPress Trac wp-trac at lists.automattic.com
Wed Jun 13 20:58:22 GMT 2007


#4409: KSES removes text after a non-tag less than sign
----------------------+-----------------------------------------------------
 Reporter:  mdawaffe  |        Owner:  anonymous  
     Type:  defect    |       Status:  new        
 Priority:  high      |    Milestone:  2.3 (trunk)
Component:  General   |      Version:  2.2        
 Severity:  critical  |   Resolution:             
 Keywords:            |  
----------------------+-----------------------------------------------------
Comment (by markjaquith):

 If you can do it outside of KSES without too much fuss or processing
 overhead, then we should go that route.

 Note for posterity: HTML Purifier
 [http://htmlpurifier.org/demo.php?html=%3Cp%3E1+%3C+2&strict=1 doesn't
 handle this any better] than KSES, even though it does offer XHTML well-
 formedness and validity plus XSS filtering all in one package.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/4409#comment:6>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list