Home  >  Article  >  Backend Development  >  Introduction to CI framework security filtering functions

Introduction to CI framework security filtering functions

不言
不言Original
2018-06-29 10:21:471671browse

这篇文章主要介绍了CI框架安全过滤函数,结合实例形式分析了CodeIgniter框架去空、防止XSS的函数定义与使用方法,并附带了原生PHP进行各种常见安全过滤相关操作技巧,需要的朋友可以参考下

本文实例讲述了CI框架安全过滤函数。分享给大家供大家参考,具体如下:

1、CI框架版本:

/**
* 自动过滤变量,进行XSS,去空
* 支持:单个字符串,多维数组,数字
* @param type $param = '常规字符串' 或 array('字符串1','字符串2');
* @return string|array
*/
final protected function html_trim($param='')
{
  if(is_array($param) && !empty ($param)){
    return ($param);
  }
  if(is_string($param)){
    return htmlspecialchars(trim($param));
  }
  if(is_numeric($param))
  {
    return (int)$param;
  }
  return $param;
}

使用方式为:

$this->html_trim($this->input->post('refer_url',TRUE));

由于第二个参数为TRUE,默认已经进行了xss过滤

2、原生PHP版本

/**
 * 安全过滤类-过滤javascript,css,iframes,object等不安全参数 过滤级别高
 * @param string $value 需要过滤的值
 * @return string
 */
function fliter_script($value) {
   $value = preg_replace("/(javascript:)?on(click|load|key|mouse|error|abort|move|unload|change|dblclick|move|reset|resize|submit)/i","&111n\\2",$value);
   $value = preg_replace("/(.*?)<\/script>/si","",$value);
   $value = preg_replace("/(.*?)<\/iframe>/si","",$value);
   $value = preg_replace ("//iesU", &#39;&#39;, $value);
   return $value;
}
/**
 * 安全过滤类-过滤HTML标签
 * @param string $value 需要过滤的值
 * @return string
 */
function fliter_html($value) {
   if (function_exists(&#39;htmlspecialchars&#39;)) return htmlspecialchars($value);
   return str_replace(array("&", &#39;"&#39;, "&#39;", "<", ">"), array("&", "\"", "&#39;", "<", ">"), $value);
}
/**
 * 安全过滤类-对进入的数据加下划线 防止SQL注入
 * @param string $value 需要过滤的值
 * @return string
 */
function fliter_sql($value) {
   $sql = array("select", &#39;insert&#39;, "update", "delete", "\&#39;", "\/\*",
     "\.\.\/", "\.\/", "union", "into", "load_file", "outfile");
   $sql_re = array("","","","","","","","","","","","");
   return str_replace($sql, $sql_re, $value);
}
/**
 * 安全过滤类-通用数据过滤
 * @param string $value 需要过滤的变量
 * @return string|array
 */
function fliter_escape($value) {
 if (is_array($value)) {
   foreach ($value as $k => $v) {
      $value[$k] = self::fliter_str($v);
   }
 } else {
   $value = self::fliter_str($value);
 }
 return $value;
}
/**
 * 安全过滤类-字符串过滤 过滤特殊有危害字符
 * @param string $value 需要过滤的值
 * @return string
 */
function fliter_str($value) {
   $badstr = array("\0", "%00", "\r", &#39;&&#39;, &#39; &#39;, &#39;"&#39;, "&#39;", "<", ">", "  ", "%3C", "%3E");
   $newstr = array(&#39;&#39;, &#39;&#39;, &#39;&#39;, &#39;&&#39;, &#39; &#39;, &#39;"&#39;, &#39;&#39;&#39;, "<", ">", "  ", "<", ">");
   $value = str_replace($badstr, $newstr, $value);
   $value = preg_replace(&#39;/&((#(\d{3,5}|x[a-fA-F0-9]{4}));)/&#39;, &#39;&\\1&#39;, $value);
   return $value;
}
/**
 * 私有路劲安全转化
 * @param string $fileName
 * @return string
 */
 function filter_dir($fileName) {
 $tmpname = strtolower($fileName);
 $temp = array(&#39;:/&#39;,"\0", "..");
 if (str_replace($temp, &#39;&#39;, $tmpname) !== $tmpname) {
   return false;
 }
 return $fileName;
}
/**
 * 过滤目录
 * @param string $path
 * @return array
 */
public function filter_path($path) {
   $path = str_replace(array("&#39;",&#39;#&#39;,&#39;=&#39;,&#39;`&#39;,&#39;$&#39;,&#39;%&#39;,&#39;&&#39;,&#39;;&#39;), &#39;&#39;, $path);
   return rtrim(preg_replace(&#39;/(\/){2,}|(\\\){1,}/&#39;, &#39;/&#39;, $path), &#39;/&#39;);
}
/**
 * 过滤PHP标签
 * @param string $string
 * @return string
 */
public function filter_phptag($string) {
   return str_replace(array(&#39;&#39;), array(&#39;<?&#39;, &#39;?>&#39;), $string);
}
/**
 * 安全过滤类-返回函数
 * @param string $value 需要过滤的值
 * @return string
 */
public function str_out($value) {
   $badstr = array("<", ">", "%3C", "%3E");
   $newstr = array("<", ">", "<", ">");
   $value = str_replace($newstr, $badstr, $value);
   return stripslashes($value); //下划线
}

以上就是本文的全部内容,希望对大家的学习有所帮助,更多相关内容请关注PHP中文网!

相关推荐:

CI框架AR数据库操作常用函数总结

关于CI框架常用的函数封装

PHP取整函数之ceil,floor,round,intval的区别解析

The above is the detailed content of Introduction to CI framework security filtering functions. For more information, please follow other related articles on the PHP Chinese website!

Statement:
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn