Sanitize input from codeMirror edit field
-
I’m planning to allow loggedin users in the admin area to edit a section of a template ( html / css code and some <% %> tags ) that’s used to display data from my plugin. I found that codeMirror ships with WordPress, so that’s what I plan to use.
Since users will be editing the template code ( which will be saved in the database ) I wonder how / if I should deal with the possible <script> tags etc that they may add. sanitize_text_field / strip_tags are useless, since the template does contain tags, but there’s no need for <link>, <iframe>, <script> etc.
I noticed strip_tags allows you to provide a list of allowed tags, which would be one way to deal with it. But one plugin that I found that also uses codeMirror doesn’t bother to sanitize anything, I tried to make it trigger an alert() on the frontpage, and this worked. They probably feel that since we are only dealing with authenticated users in the admin area, it’s their own responsibility what the include in the template code.
I kind of split on what the best way to deal with this. Either provide a list of allowed tags ( very much leaning towards this ), or because they are authenticated users allow them to do whatever they want?
Any ideas / suggestions?
- The topic ‘Sanitize input from codeMirror edit field’ is closed to new replies.