Content Management
Sanitary comments
3 Oct 2002
Brad Choate’s got another Movable Type plugin out and this one enhances the security of your Weblog. The Sanitize Plugin allows you to specify a list of HTML tags that are allowed in the output of any MT tag—any other tags are stripped out.
If you allow people to use HTML in their comments, they can insert malicious code like <script>location.replace = 'http://somesite.com/';</script>
. Using the Sanitize plugin, you can prevent <script>
tags from ever appearing in your comments.
The plugin also makes sure that all tags that are opened are also closed. That way if someone accidentally leaves out a </b>
it doesn’t bold the rest of the page.
This is also a good plugin to use on blogs that have multiple authors, on your trackbacks, and anywhere else that people other than you have access to enter HTML on your site.