详细代码如下:
<?php <BR>abstract class Filter { //filter parent class <BR>private $blackstr = array(); <BR>private $whitestr = array(); <BR>function filtit($str) { <BR>//do something <BR>} <BR>} <BR>class LoginFilter extends Filter { //for user login filte username(过滤注册的用户名) <BR>function filtit($str) { <BR>$this -> blackstr = array( <BR>´/[\x7f-\xff]/´, //filter chinese include chinese symbol <BR>´/\W/´ //filter all english symbol <BR>); <BR>retur<strong style="color:transparent">本文来源gao@daima#com搞(%代@#码@网&</strong><strong>搞gaodaima代码</strong>n preg_replace($this->blackstr, ´´, $str); <BR>} <BR>} <BR>class EditorFilter extends Filter { //for article editor filter(过滤在线编辑器内容) <BR>function filtit($str) { <BR>$this -> blackstr = array( <BR>´/\&/´, <BR>´/\´/´, <BR>´/\"/´, <BR>´/\</´, <BR>´/\>/´, <BR>´/\\\\/´, <BR>´/\//´, <BR>´/-/´, <BR>´/\*/´, <BR>´/ /´ <BR>); <BR>$this -> whitestr = array( <BR>´&´, <BR>´'´, <BR>´"´, <BR>´<´, <BR>´>´, <BR>´\´, <BR>´/´, <BR>´-´, <BR>´*´, <BR>´ ´ <BR>); <BR>return preg_replace($this->blackstr, $this -> whitestr, $str); <BR>} <BR>} <BR>class SQLFilter extends Filter { //for filte sql query string(过滤如查询或其它sql语句) <BR>function filtit($str) { <BR>$this -> blackstr = array( <BR>´/\´/´, <BR>´/-/´ <BR>); <BR>return preg_replace($this->blackstr, ´´, $str); <BR>} <BR>} <BR>class FileNameFilter extends Filter { //for filte a file name(过滤文件名如下载文件名) <BR>function filtit($str) { <BR>$this -> blackstr = array( <BR>´/[^A-za-z0-9_\.]|\\\\|\^|\[|\]/´ <BR>); <BR>return preg_replace($this->blackstr, ´´, $str); <BR>} <BR>} <BR>?> <BR>
使用方法如:
$filter = new FileNameFilter(); //定义实例 <BR>$downFile = $filter->filtit($_GET[´fn´]); //调用过滤方法 <BR>