Skip to content

Commit 623d9a2

Browse files
committed
MC-41412: Improve inline translation.
1 parent 5262ff6 commit 623d9a2

File tree

2 files changed

+5
-3
lines changed

2 files changed

+5
-3
lines changed

lib/internal/Magento/Framework/Filter/Input/MaliciousCode.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,9 +30,9 @@ class MaliciousCode implements \Zend_Filter_Interface
3030
'/(ondblclick|onclick|onkeydown|onkeypress|onkeyup|onmousedown|onmousemove|onmouseout|onmouseover|onmouseup|'.
3131
'onload|onunload|onerror)=[^<]*(?=\/*\>)/Uis',
3232
//tags
33-
'/<\/?\??(script|meta|link|frame|iframe|object).*>/Uis',
33+
'/<\/?(script|meta|link|frame|iframe|object).*>/Uis',
3434
//scripts
35-
'/<\/?\??(php).*>/Uis',
35+
'/<\?{1}\s*?(php|=).*>/Uis',
3636
//base64 usage
3737
'/src=[^<]*base64[^<]*(?=\/*\>)/Uis',
3838
];

lib/internal/Magento/Framework/Filter/Test/Unit/Input/MaliciousCodeTest.php

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -114,7 +114,9 @@ public function filterDataProvider()
114114
'alert(1);',
115115
],
116116
'Nested scripts' => [
117-
'<?php echo "test"?>',
117+
'<?php echo "test" ?>',
118+
'',
119+
'<?= "test" ?>',
118120
'',
119121
],
120122
];

0 commit comments

Comments
 (0)