通过这种方式,您可以过滤掉任何潜在危险的 html 标签,剩下的内容无法在数据库查询或 HTML 输出中执行。通过将其放在 HTML 页面中,您可以完全控制标签的编写方式。
This way you can filter out any potentially dangerous html tags, what remains cannot be executed in a database query or in an HTML output. Giving it out in an HTML page, you have full control of how the tags should be written.
发布评论
评论(3)
通过这种方式,您可以过滤掉任何潜在危险的 html 标签,剩下的内容无法在数据库查询或 HTML 输出中执行。通过将其放在 HTML 页面中,您可以完全控制标签的编写方式。
This way you can filter out any potentially dangerous html tags, what remains cannot be executed in a database query or in an HTML output. Giving it out in an HTML page, you have full control of how the tags should be written.
避免由于暴露所有完整的 HTML 词汇而可能发生的
跨站点脚本问题
以及其他此类相关问题Avoidance against
cross site scripting issue
and other such related issue that can occur due to exposing all the complete HTML vocab它们是定义数据的简单方法,并且通常易于操作。
They're a simple way to define data and usually easy to manipulate.