From: eden li Date: 2006-10-09T14:36:03+09:00 Subject: Re: Stripping unwanted html Glad I could help. One security-related caveat. The method I posted doesn't strip attributes, so it may be possible for someone to "hack" your site by putting javascript onto one of the allowed tags. You can fix that by changing the last line of the first branch of the if statement from "text" to "sanitize(text)", eg: if html.index("<") ... sanitize(text) else ... Wild Al wrote: > I found this method very useful; it is exactly what I needed. Thanks. > To all others: your suggestions helped too, especially in understanding > ruby. Thanks again...