From: "Florian Groß" Date: 2005-04-16T06:29:54+09:00 Subject: Re: RedCloth, BlueCloth... Navindra Umanee wrote: > Anyone know if there's any support to verify whether the HTML and URLs > are safe -- in the sense that they aren't JavaScript hacks or image > insertions or the such? > > This would be useful if using *Cloth in a web-application where you > might want to severely restrict the kind of HTML that can get used. AFAIK RedCloth has multiple modes. It can either disallow HTML and inline styles completely or use a tag filter list. While the latter might sound like the more graceful of the two approaches there is IMHO lots of subtle cases where browsers will parse obscure syntax different than HTML filters which could lead to malicious code slipping through. Just have a look at all the trouble eBay has been having despite their claim of already using heavy-weight filters. Allowing CSS might appear safe at first, but the major browsers all support schemes for behavior binding at the style level and Internet Explorer also allows for interpolation of arbitrary JavaScript code via expression().