View Helpers
stripTags()
Signature
Section titled “Signature”stripTags() — returns string
Available in: controller
Category: Sanitization Functions
Description
Section titled “Description”Removes all HTML tags from a string.
Defaults to false (configurable per-function via
set(functionName=“stripTags”, encode=true)). These helpers strip
markup; they are NOT an escaping strategy — when the goal is XSS-safe
output, use h() / hAttr() instead.
Parameters
Section titled “Parameters”| Name | Type | Required | Default | Description |
|---|---|---|---|---|
html | string | yes | — | The HTML to remove tag markup from. |
encode | boolean | no | true | Whether to HTML-encode the remaining text after stripping. |
Examples
Section titled “Examples”// 1. Strip all HTML tags from a string, leaving plain text
result = stripTags('<strong>CFWheels</strong> is a framework for <a href="http://www.adobe.com/products/coldfusion">ColdFusion</a>.');
// result -> "CFWheels is a framework for ColdFusion."
// 2. Strip tags from a richer HTML fragment
result = stripTags('<h1>Welcome</h1><p>This is a <em>great</em> framework.</p>');
// result -> "WelcomeThis is a great framework."
// 3. Strip tags while skipping XSS encoding (e.g. when you trust the source HTML)
result = stripTags('<p>Hello, <strong>world</strong>!</p>', encode=false);
// result -> "Hello, world!"