modX.sanitizeString
Last updated not available | Page history | Improve this page | Report an issue
Support the team building MODX with a monthly donation.
The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.
Backers
Budget
$194 per month—let's make that $500!
Learn moremodX::sanitizeString¶
Removes HTML tags from a string, deletes a fixed list of characters, then keeps only letters, digits, _, -, ., /, spaces and [. Characters are dropped, never escaped, so the result can go straight into a query or a class key.
Core uses it on request values that end up in SQL or manager logic, such as namespace foreign keys and manager login flags.
Syntax¶
string sanitizeString (string $str, [array $chars = ['/', "'", '"', '(', ')', ';', '>', '<']], [string $allowedTags = ''])
-
$str(string) value to sanitize -
$chars(array) characters deleted after tag stripping; the default list is shown in the signature -
$allowedTags(string) tags kept by PHPstrip_tags(), by default none are kept
Example¶
$clean = $modx->sanitizeString('<b>foobar</b> (staff)');
// $clean === 'foobar staff'
See Also¶
Support the team building MODX with a monthly donation.
The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.
Backers
Budget
$194 per month—let's make that $500!
Learn more










