HTMLPurifier iframe Vimeo和Youtube视频 [英] HTMLPurifier iframe Vimeo and Youtube video
本文介绍了HTMLPurifier iframe Vimeo和Youtube视频的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!
问题描述
如何使用HTMLPurifier过滤xss,还允许使用iframe Vimeo和Youtube视频?
How can I use HTMLPurifier to filter xss but also to allow iframe Vimeo and Youtube video?
require_once 'htmlpurifier/library/HTMLPurifier.auto.php';
$config = HTMLPurifier_Config::createDefault();
$config->set('HTML.Trusted', true);
$config->set('Filter.YouTube', true);
$config->set('HTML.DefinitionID', '1');
$config->set('HTML.SafeObject', 'true');
$config->set('Output.FlashCompat', 'true');
$config->set('HTML.FlashAllowFullScreen', 'true');
$purifier = new HTMLPurifier($config);
$temp = $purifier->purify($temp);
推荐答案
HTMLPurifier版本4.4.0有新的配置指令允许YouTube和Vimeo iframe:
HTMLPurifier version 4.4.0 has new configuration directives to allow YouTube and Vimeo iframes:
//allow iframes from trusted sources
$cfg->set('HTML.SafeIframe', true);
$cfg->set('URI.SafeIframeRegexp', '%^(https?:)?//(www\.youtube(?:-nocookie)?\.com/embed/|player\.vimeo\.com/video/)%'); //allow YouTube and Vimeo
- http://htmlpurifier.org/live/configdoc/plain.html#HTML.SafeIframe
- http://htmlpurifier.org/live/configdoc/ plain.html#URI.SafeIframeRegexp
- http://htmlpurifier.org/live/configdoc/plain.html#HTML.SafeIframe
- http://htmlpurifier.org/live/configdoc/plain.html#URI.SafeIframeRegexp
这篇关于HTMLPurifier iframe Vimeo和Youtube视频的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!
查看全文