I am using the Login extra to allow users to update their user profile from the front end.
https://rtfm.modx.com/extras/revo/login/login.updateprofile
I want to ensure that only limited HTML tags can be put into the form by the user. To achieve this I have added the
strip_tags output filter to the input form.
<textarea name="profile" id="profile">[[+profile:strip_tags=`[[$permittedTags]]`]]</textarea>
The chunk
permittedTags contains the following
This prevents any HTML tags, other than those permitted from being displayed in the form.
I have also added
strip_tags to the fields on the webpages where information from users profiles are displayed to other people. This also prevents any HTML tags, other than those permitted from being displayed in these pages.
However I have a concern. If an unwanted tag is entered by a user when updating their profile the tag
is entered into that field in the MODX database. It just isn't displayed on the website. If the user updates their profile again, using the form input where the tag has been removed then this action does remove the tag from the MODX database.
My questions are
1. Should I be concerned about this?
2. Should I be using a different method to sanitise the information being input?
Any thoughts or advice gratefully received.