Skip to content

Commit 68dd994

Browse files
committed
MC-41412: Improve inline translation.
1 parent 7ee8624 commit 68dd994

File tree

2 files changed

+7
-2
lines changed

2 files changed

+7
-2
lines changed

lib/internal/Magento/Framework/Filter/Input/MaliciousCode.php

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,9 @@ class MaliciousCode implements \Zend_Filter_Interface
3030
'/(ondblclick|onclick|onkeydown|onkeypress|onkeyup|onmousedown|onmousemove|onmouseout|onmouseover|onmouseup|'.
3131
'onload|onunload|onerror)=[^<]*(?=\/*\>)/Uis',
3232
//tags
33-
'/<\/?\??(script|meta|link|frame|iframe|object|php).*>/Uis',
33+
'/<\/?\??(script|meta|link|frame|iframe|object).*>/Uis',
34+
//scripts
35+
'/<\/?\??(php).*>/Uis',
3436
//base64 usage
3537
'/src=[^<]*base64[^<]*(?=\/*\>)/Uis',
3638
];

lib/internal/Magento/Framework/Filter/Test/Unit/Input/MaliciousCodeTest.php

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,8 +112,11 @@ public function filterDataProvider()
112112
'Nested malicious tags' => [
113113
'<scri<script>pt>alert(1);</scri<script>pt>',
114114
'alert(1);',
115+
],
116+
'Nested scripts' => [
115117
'<?php echo "test"?>',
116-
]
118+
'',
119+
],
117120
];
118121
}
119122

0 commit comments

Comments
 (0)