Jump to main content Jump to doc navigation

modX::sanitizeString

Removes HTML tags from a string, deletes a fixed list of characters, then keeps only letters, digits, _, -, ., /, spaces and [. Characters are dropped, never escaped, so the result can go straight into a query or a class key.

Core uses it on request values that end up in SQL or manager logic, such as namespace foreign keys and manager login flags.

Syntax

string sanitizeString (string $str, [array $chars = ['/', "'", '"', '(', ')', ';', '>', '<']], [string $allowedTags = ''])
  • $str (string) value to sanitize
  • $chars (array) characters deleted after tag stripping; the default list is shown in the signature
  • $allowedTags (string) tags kept by PHP strip_tags(), by default none are kept

Example

$clean = $modx->sanitizeString('<b>foobar</b> (staff)');

// $clean === 'foobar staff'

See Also

Support the team building MODX with a monthly donation.

The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.

Backers

  • modmore
  • STERC
  • Digital Penguin
  • Jens Wittmann – Gestaltung & Entwicklung
  • CrewMark
  • Fabian Christen
  • Sepia River Studios
  • Dannevang Digital
  • Alex
  • A. Moreno
  • Chris Fickling
  • Stéphane Jäggi
  • Murray Wood
  • Anton Tarasov
  • JT Skaggs
  • deJaya
  • Lefthandmedia
  • eydolan
  • Following Sea
  • Guido Gallenkamp
  • YJ
  • Raffy
  • Snow Creative
  • Nick Clark
  • Guest
  • Helen
  • krisznet
  • Yanni
  • Richard

Budget

$194 per month—let's make that $500!

Learn more