We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38783
    • 571 Posts
    I am using the Login extra to allow users to update their user profile from the front end.
    https://rtfm.modx.com/extras/revo/login/login.updateprofile

    I want to ensure that only limited HTML tags can be put into the form by the user. To achieve this I have added the strip_tags output filter to the input form.

    <textarea name="profile" id="profile">[[+profile:strip_tags=`[[$permittedTags]]`]]</textarea>
    


    The chunk permittedTags contains the following
    <br>,<br />,<p>,</p>
    


    This prevents any HTML tags, other than those permitted from being displayed in the form.

    I have also added strip_tags to the fields on the webpages where information from users profiles are displayed to other people. This also prevents any HTML tags, other than those permitted from being displayed in these pages.

    However I have a concern. If an unwanted tag is entered by a user when updating their profile the tag is entered into that field in the MODX database. It just isn't displayed on the website. If the user updates their profile again, using the form input where the tag has been removed then this action does remove the tag from the MODX database.

    My questions are
    1. Should I be concerned about this?
    2. Should I be using a different method to sanitise the information being input?

    Any thoughts or advice gratefully received.

      If I help you out on these forums I would be very grateful if you would consider rating me on Trustpilot: https://uk.trustpilot.com/review/andytough.com

      email: [email protected] | website: https://andytough.com
      • 3749
      • 24,544 Posts
      I would add a preHook that removes both unwanted HTML tags and all MODX tags before anything gets written to the db.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 38783
        • 571 Posts
        Quote from: BobRay at Sep 11, 2016, 03:54 AM
        I would add a preHook that removes both unwanted HTML tags and all MODX tags before anything gets written to the db.

        Hello Bob

        Thank you, I will try this. Sorry for not thanking you sooner. I have been occupied with some other stuff recently and have not been on the forums.

        Best wishes,

        Andy
          If I help you out on these forums I would be very grateful if you would consider rating me on Trustpilot: https://uk.trustpilot.com/review/andytough.com

          email: [email protected] | website: https://andytough.com