We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 22770
    • 285 Posts
    I was having trouble getting the [+tags+] placeholder to work the way I wanted it for ditto, so I wrote a very basic snippet to retrieve the relevant tag from the URL:

    <?php
    $tags = filter_input(INPUT_GET, 'tags', FILTER_SANITIZE_STRING, FILTER_FLAG_ENCODE_HIGH|FILTER_FLAG_STRIP_LOW);
    return $tags;
    ?>

    My problem is that while I know enough to know that I can’t trust user input, I don’t know enough to be sure that I can make it secure. Is the above sufficient? Should I be doing something different or something else as well?

    Thanks!