0
0
mirror of https://github.com/ezyang/htmlpurifier.git synced 2024-12-22 08:21:52 +00:00
Standards compliant HTML filter written in PHP. http://htmlpurifier.org
Go to file
Kieran db312435cb
feat: add semantic release (#307)
* Add semantic release

* fix typo

* split from matrix

* remove only on push

* remove npm plugin

* write changelog to NEWS

* list assets to include in git commit

* fix update-for-release

* lint pr title

* split release into separate workflow that runs manually

* revert ci.yml changes

* remove references to WHATSNEW

* Fix #322 - PHP 8.1 deprecation notice in HostBlacklist URIFilter (#323)

* Replace 8.1-deprecated utf8_ funcs with mbstring (#326)

* Treat PHP version numbers as strings in GitHub Actions (#327)

YAML will try to interpret numeric values as numbers, leading to `8.0` being
interpreted as `8` instead of `'8.0'`.

This doesn't result in a functional change, but cleans up the output of the
jobs a little (e.g. in the title line).

* Update to `actions/checkout@v3` (#328)

This does not introduce any functional difference and is intended as a
future-proofing change.

see https://github.com/actions/checkout/releases/tag/v3.0.0

* Fix test selection logic in tests/test_files.php (#329)

Selecting the `fstools` tests also executed the `htmlt` tests.

* Fix some more PHP 8.2 deprecations (#330)

* Define HTMLPurifier_AttrTransform_SafeParam::$wmode

This fixes a PHP 8.2 deprecation.

* Define HTMLPurifier_DefinitionCache_DecoratorHarness::$cache

This fixes a PHP 8.2 deprecation.

* Define HTMLPurifier_DefinitionCache_DecoratorHarness::$mock

This fixes a PHP 8.2 deprecation.

* Define HTMLPurifier_DefinitionCache_DecoratorHarness::$def

This fixes a PHP 8.2 deprecation.

* Define HTMLPurifier_EntityParserTest::$_entity_lookup

This fixes a PHP 8.2 deprecation.

* Increase minimum requirement to PHP 5.6 (#331)

* Add contenteditable attribute definition (#332)

* Add contenteditable attribute definition

* gate behind html.trusted

* use enum

* Fix creation of dynamic property (#333)

* Fix creation of dynamic property (#337)

* Add PHP 8.2 to CI (#335)

* Add PHP 8.2 to CI

see ezyang/htmlpurifier#334

* Add PHP 8.2 to composer.json

* Fix contenteditable attribute definition (#336)

* Run CSSTidy tests on CI (#338)

* Run CSSTidy tests on CI

* update dirname

* use compopser instead of git clone

* use composer

* use test-settings.sample.php

* enable ext-intl

* disable Net_IDNA2

* Release 4.15.0

Signed-off-by: Edward Z. Yang <ezyang@mit.edu>

Signed-off-by: Edward Z. Yang <ezyang@mit.edu>
Co-authored-by: John Flatness <john@zerocrates.org>
Co-authored-by: Tim Düsterhus <duesterhus@woltlab.com>
Co-authored-by: Tim Düsterhus <timwolla@googlemail.com>
Co-authored-by: Edward Z. Yang <ezyang@mit.edu>
2022-09-18 02:44:00 -04:00
.github/workflows feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
art [2.0.1] Implement haphazard error collection for AttrValidator. 2007-06-27 02:03:15 +00:00
benchmarks .htaccess support apache 2.4+ (#190) 2018-11-11 14:55:13 -05:00
configdoc Release 4.15.0 2022-09-18 02:23:57 -04:00
docs Supported hundreds of nested HTML (#202) 2019-07-14 13:15:31 -04:00
extras PHP 8.1: fix various deprecations/errors in newest version of PHP (#310) 2022-04-08 13:48:12 -04:00
library Release 4.15.0 2022-09-18 02:23:57 -04:00
maintenance feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
plugins Supported hundreds of nested HTML (#202) 2019-07-14 13:15:31 -04:00
smoketests Run CSSTidy tests on CI (#338) 2022-09-14 20:55:41 -07:00
tests Run CSSTidy tests on CI (#338) 2022-09-14 20:55:41 -07:00
.gitattributes feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
.gitignore Improve gitignore. 2013-10-13 00:18:11 -07:00
composer.json Run CSSTidy tests on CI (#338) 2022-09-14 20:55:41 -07:00
CREDITS Add vim modelines to all files. 2008-12-06 04:24:59 -05:00
Doxyfile Release 4.15.0 2022-09-18 02:23:57 -04:00
INSTALL Delete references to PHP 5.1 in INSTALL. 2018-11-11 16:56:06 -05:00
INSTALL.fr.utf8 Update PHP version in INSTALL (#195) 2018-10-23 20:03:41 -04:00
LICENSE Add vim modelines to all files. 2008-12-06 04:24:59 -05:00
NEWS Release 4.15.0 2022-09-18 02:23:57 -04:00
package.php feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
phpdoc.ini Add vim modelines to all files. 2008-12-06 04:24:59 -05:00
README.md PHP 8 Support (#297) 2021-07-20 09:40:50 -04:00
release.config.js feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
test-settings.sample.php Run CSSTidy tests on CI (#338) 2022-09-14 20:55:41 -07:00
TODO Release 4.8.0 2016-07-16 05:58:58 -07:00
update-for-release feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
VERSION Release 4.15.0 2022-09-18 02:23:57 -04:00
WYSIWYG Add vim modelines to all files. 2008-12-06 04:24:59 -05:00

HTML Purifier Build Status

HTML Purifier is an HTML filtering solution that uses a unique combination of robust whitelists and aggressive parsing to ensure that not only are XSS attacks thwarted, but the resulting HTML is standards compliant.

HTML Purifier is oriented towards richly formatted documents from untrusted sources that require CSS and a full tag-set. This library can be configured to accept a more restrictive set of tags, but it won't be as efficient as more bare-bones parsers. It will, however, do the job right, which may be more important.

Places to go:

  • See INSTALL for a quick installation guide
  • See docs/ for developer-oriented documentation, code examples and an in-depth installation guide.
  • See WYSIWYG for information on editors like TinyMCE and FCKeditor

HTML Purifier can be found on the web at: http://htmlpurifier.org/

Installation

Package available on Composer.

If you're using Composer to manage dependencies, you can use

$ composer require ezyang/htmlpurifier