Re: [Catalyst] HTML encoding parameters

2014-06-29 Thread Charlie Garrison
Good evening, On 28/06/14 at 8:13 PM -0700, bill hauck wbha...@yahoo.com wrote: Is there a module that does this to all parameters at once? You want one of these (there are more on cpan too): https://metacpan.org/pod/HTML::Scrubber https://metacpan.org/pod/HTML::Lint Charlie --

Re: [Catalyst] HTML encoding parameters

2014-06-29 Thread Mark Ellis
I've had really good results with HTML::StripScripts::Parser, you can set allowed tags, attributes and stop JavaScript injection. You can also set allowed attributes on certain tags only, it's really flexible On 29 Jun 2014 05:14, bill hauck wbha...@yahoo.com wrote: Hi. Please forgive me if

[Catalyst] HTML encoding parameters

2014-06-28 Thread bill hauck
Hi. Please forgive me if this is an easy one.  It's late and I haven't found any mention of it. I'd like to encode form fields so that only the standard bold, italic, underline, list, etc. are allowed and and script, style, etc. tags are encoded.  Also, I'd like to only let the base tags