+ *
+ * HTML Validation (i.e. PHP HTML Purifier)
+ */
+ /*public static function validate_html($untrusted_html)
+ {
+ }*/
+ /**
+ * Context: Safe HTML attributes
+ * e.g.
+ *
+ * Limit to whitelisted attributes:
+ * align, alink, alt, bgcolor, border, cellpadding, cellspacing, class,
+ * color, cols, colspan, coords, dir, face, height, hspace, ismap, lang,
+ * marginheight, marginwidth, multiple, nohref, noresize, noshade,
+ * nowrap, ref, rel, rev, rows, rowspan, scrolling, shape, span, summary,
+ * tabindex, title, usemap, valign, value, vlink, vspace, width.
+ *
+ * Except for alphanumeric characters, escape all characters with the
+ * HH; HTML entity format, including spaces
+ *
+ * Apply additional validation to href and src attributes
+ */
+ public const HTML_ATTR_WHITELIST = [
+ 'align', 'alink', 'alt', 'bgcolor', 'border', 'cellpadding',
+ 'cellspacing', 'class', 'color', 'cols', 'colspan', 'coords', 'dir',
+ 'face', 'height', 'hspace', 'ismap', 'lang', 'marginheight',
+ 'marginwidth', 'multiple', 'nohref', 'noresize', 'noshade', 'nowrap',
+ 'ref', 'rel', 'rev', 'rows', 'rowspan', 'scrolling', 'shape', 'span',
+ 'summary', 'tabindex', 'title', 'usemap', 'valign', 'value', 'vlink',
+ 'vspace', 'width',
+ 'href', 'src',
+ ];
+ public static function htmlAttr(
+ string $attr,
+ mixed $untrusted_data,
+ bool $wrap = true
+ ): string {
+ $attr = mb_strtolower($attr);
+ if (!in_array($attr, static::HTML_ATTR_WHITELIST, true)) {
+ throw new \InvalidArgumentException('HTML attribute is not whitelisted');
+ }
+ if ($attr === 'href' || $attr === 'src') {
+ $validated = static::validateUrl($untrusted_data);
+ }
+ $encoded_data = static::encode($untrusted_data, 'html');
+ return $wrap ? ' ' . $attr . '="' . $encoded_data . '"' : $encoded_data;
+ }
+ /**
+ * Context: Untrusted URL in a `src` or `href` attribute
+ * e.g.
+ * e.g. link
+ *
+ * Whitelist https URLs only
+ *
+ * Apply additional whitelisting, canonicalization and anti-virus checks
+ * depending on the use-case
+ */
+ public static function validateUrl(mixed $untrusted_data): bool
+ {
+ if (!is_string($untrusted_data)) {
+ $untrusted_data = strval($untrusted_data);
+ }
+ $protocol = mb_substr($untrusted_data, 0, 8);
+ if ($protocol !== 'https://') {
+ throw new \InvalidArgumentException('URL is not HTTPS');
+ }
+ return true;
+ }
+ /**
+ * Context: JavaScript variable
+ * e.g.
+ * e.g.
+ *
+ * Do not use this when outputting JSON in HTML. Instead, use the dedicated
+ * jsonInHtml method
+ *
+ * Ensure JavaScript variables are quoted
+ *
+ * Except for alphanumeric characters, escape all characters with the
+ * \uXXXX unicode escaping format
+ *
+ * Avoid backslash encoding
+ */
+ public static function jsVar(mixed $untrusted_data): string
+ {
+ $encoded_data = static::encode($untrusted_data, 'unicode');
+ return $encoded_data;
+ }
+ /**
+ * Context: CSS value
+ * e.g.
+ *
+ * CSS escaping supports \XX and \XXXXXX. Zero-pad to 6 characters
+ */
+ public static function cssValue(mixed $untrusted_data): string
+ {
+ $encoded_data = static::encode($untrusted_data, 'css');
+ return $encoded_data;
+ }
+ /**
+ * Context: URL parameter
+ * e.g. link
+ *
+ * Except for alphanumeric characters, escape all characters with the
+ * %HH escaping format
+ */
+ public static function urlParam(mixed $untrusted_data): string
+ {
+ $encoded_data = static::encode($untrusted_data, 'url');
+ return $encoded_data;
+ }
+ /**
+ * Context: JSON in HTML
+ * e.g.
+ * e.g. var data = JSON.parse(document.getElementById('data').textContent);
+ *
+ * Encode entities: & < > " '
+ *
+ * Output JSON inside a hidden element before calling JSON.parse(el.textContent)
+ *
+ * @param mixed $untrusted_data
+ */
+ public static function jsonInHtml(mixed $untrusted_data): string
+ {
+ return json_encode($untrusted_data, $flags) ?: '[]';
+ }
+# \thisispiers\Xss\Escape
+A PHP implementation of [OWASP's Cross Site Scripting Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html)
+Released under LGPL v3.0. Requires PHP >= 7.1 and mbstring extension
+Install with Composer `composer require thisispiers/xss-escape`
+## Usage
+Untrusted data should be encoded differently depending on context. This library provides a static method for each context.
+### Text in HTML Body
+htmlBody(mixed $untrusted_data): string
+`$untrusted_data` is cast to string
+### HTML in HTML body
+i.e. `
+Use a full HTML validator in this context, such as [HTML Purifier](https://github.com/ezyang/htmlpurifier) or [DOMPurify](https://github.com/cure53/DOMPurify)
+### Safe HTML attributes
+i.e. ``
+htmlAttr(string $attr, mixed $untrusted_data, bool $wrap = true): string
+`$attr` must be one of
+- align
+- alink
+- alt
+- bgcolor
+- border
+- cellpadding
+- cellspacing
+- class
+- color
+- cols
+- colspan
+- coords
+- dir
+- face
+- height
+- href (see [URLs](#URLs))
+- hspace
+- ismap
+- lang
+- marginheight
+- marginwidth
+- multiple
+- nohref
+- noresize
+- noshade
+- nowrap
+- ref
+- rel
+- rev
+- rows
+- rowspan
+- scrolling
+- shape
+- span
+- src (see [URLs](#URLs))
+- summary
+- tabindex
+- title
+- usemap
+- valign
+- value
+- vlink
+- vspace
+- width
+`$untrusted_data` is cast to string
+If `$wrap` is `true`, the returned string is prefixed by a space, the attribute name, an equal sign and wrapped in double quote marks i.e. `` value="ENCODED DATA"``.
+### URLs
+URLs in `src` or `href` HTML attributes i.e. `` or `link`
+validateUrl(mixed $untrusted_data): bool
+`$untrusted_data` is cast to string
+Untrusted URLs are currently only checked to be HTTPS. This is a crude check to avoid becoming a full URL parsing library. It is highly recommended that you run more sophisticated validation on your untrusted URLs, such as rejecting URLs by hostname.
+### JavaScript variables
+i.e. `` or ``
+jsVar(mixed $untrusted_data): string
+`$untrusted_data` is cast to string
+### CSS values
+i.e. `
+cssValue(mixed $untrusted_data): string
+`$untrusted_data` is cast to string
+### URL parameters
+i.e. `link`
+urlParam(mixed $untrusted_data): string
+`$untrusted_data` is cast to string
+### JSON in HTML
+jsonInHtml(mixed $untrusted_data): string
+`$untrusted_data` is cast to string
+Output JSON inside a hidden element before calling `JSON.parse` e.g.
+## Contributing & Help
+Don't expect frequent updates, but pull requests for security and performance improvements are welcome!
+There is no guarantee this library complies with the latest OWASP cheat sheet recommendations. Create an issue if you think it's out of date, or start a pull request.
+To save keystrokes, you might want to create an alias for this class
+e.g. `class_alias('\\thisispiers\Xss\\Escape', '\\esc');`
\ No newline at end of file
+ "name": "thisispiers/xss-escape",
+ "description": "A PHP implementation of OWASP Cross Site Scripting Prevention Cheat Sheet",
+ "license": "LGPL-3.0-only",
+ "require": {
+ "php": ">=7.1",
+ "ext-mbstring": "*"
+ },
+ "autoload": {
+ "psr-4": {
+ "thisispiers\\Xss\\": ""
+ }
+ }
\ No newline at end of file