File: |
tests/XssTest.php |
Role: |
Class source |
Content type: |
text/plain |
Description: |
Class source |
Class: |
PHP Anti XSS Filter
Remove tags from HTML that may cause XSS attacks |
Author: |
By Lars Moelleken |
Last change: |
[+]: optimize "_do_never_allowed_afterwards" -> thanks @Fahl-Design
-> I only fixed the "valid string without attribute XSS" in tags, because "\s*onEnd\s*" could be added into html tags.
#99 fix tests (7, basic) run
Signed-off-by: Benjamin Fahl <git@fahl-design.de>
#99 code style
Signed-off-by: Benjamin Fahl <git@fahl-design.de>
#99 add todo and prepare tests for "_do_never_allowed_afterwards" false positive cases
Signed-off-by: Benjamin Fahl <git@fahl-design.de>
#99 optimize regex to "_sanitize_naughty_javascript" by adding a negative look behind
- add test cases
- change js test result (no longer false positive)
Signed-off-by: Benjamin Fahl <git@fahl-design.de>
Apply fixes from StyleCI
[+]: "AntiXSS" -> move more static data into the object
-> workaround for issue #95
[+]: added one more test
Merge remote-tracking branch 'origin/master' into master
* origin/master:
Update codecov/codecov-action action to v2
Update shivammathur/setup-php action to v2.16.0
[*]: hack for PHP 8.1
[+]: fix issue #83
[+]: optimize decoding the html-tags
thanks @gharlan for the fix: https://github.com/voku/anti-xss/issues/85#issuecomment-981093761
|
Date: |
3 months ago |
Size: |
340,658 bytes |
|
|
|