Alright, I'd like to allow users to post comments with HTML, but also avoid things like abuse via scripts, iframes, and inline events.

How would I do this?