Giter Site home page Giter Site logo

bnomei / kirby3-htmlpurifier Goto Github PK

View Code? Open in Web Editor NEW
3.0 2.0 0.0 494 KB

Static class method, Uniform-Guard and Field-Method to filter your "dirty" HTML inputs to "clean" HTML.

License: MIT License

PHP 100.00%
kirby3 kirby3-cms kirby3-plugin form submit uniform sanitize filter security xss

kirby3-htmlpurifier's Introduction

Kirby 3 HtmlPurifier

Release Downloads Build Status Coverage Status Maintainability Twitter

Static class method, Uniform-Guard and Field-Method to filter your "dirty" HTML inputs to "clean" HTML.

strip_tags and PHP Input Filter are not good enough for you? Installing a plugin that has a dependency with lots of code does not bother you? You are willing to take the performance hit if you use it? Read on then...

Commerical Usage


Support open source!

This plugin is free but if you use it in a commercial project please consider to sponsor me or make a donation.
If my work helped you to make some cash it seems fair to me that I might get a little reward as well, right?

Be kind. Share a little. Thanks.

‐ Bruno
 
M O N E Y
Github sponsor Patreon Buy Me a Coffee Paypal dontation Hire me

Installation

  • unzip master.zip as folder site/plugins/kirby3-htmlpurifier or
  • git submodule add https://github.com/bnomei/kirby3-htmlpurifier.git site/plugins/kirby3-htmlpurifier or
  • composer require bnomei/kirby3-htmlpurifier

Usage PHP

$cleanHtml = \Bnomei\HtmlPurifier::purify($dirtyHtml);

Usage Uniform-Guard

Because of the plugin loading order the htmlPurifyGuard will only be available with composer installations of this plugin.

$form = new \Uniform\Form;

if (kirby()->request()->is('POST')) {

    $form->honeypotGuard() // needs to be called explicitly now
        ->htmlPurifyGuard(); // purified all data

    if ($form->success()) {
        // ...
    }
}

Usage Field-Method

$dirtHtml = (string) $page->myfield();
$cleanHtml = (string) $page->myfield()->htmlPurify();
$cleanHtml = (string) $page->myfield()->kirbytext()->htmlPurify();

Usage with KQL for headless

If you want to make extra sure your html output to headless is valid html you can purify your fields. Be advised that this will come with a performance penalty since purification is no simple task.

⚠️ All proprietary elements (<template>, ...) and attributes (srcset, sizes, data-*, x-*:, @*:, ...) will be removed!

KQL Query

{
    "query": "page('photography')",
    "select": {
        "url": true,
        "title": true,
        "textWithPurifiedHtml": "page.text.kirbytext.htmlPurify"
    }
}

Example: Vue

<div v-html="textWithPurifiedHtml"></div>

Settings

bnomei.htmlpurifier. Default Description
config callback overwrite this to adjust the config of used HtmlPurifier dependency

Dependecies

Disclaimer

This plugin is provided "as is" with no guarantee. Use it at your own risk and always test it yourself before using it in a production environment. If you find any issues, please create a new issue.

License

MIT

It is discouraged to use this plugin in any project that promotes racism, sexism, homophobia, animal abuse, violence or any other form of hate speech.

kirby3-htmlpurifier's People

Contributors

bnomei avatar

Stargazers

 avatar  avatar  avatar

Watchers

 avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.