mirror of
https://github.com/EGroupware/egroupware.git
synced 2024-12-27 00:58:56 +01:00
special handling for $_POST[json_data] in _check_script_tag, to decend into its decoded content, fixing json direct might break json syntax
This commit is contained in:
parent
8643b08e90
commit
1971186597
@ -1464,6 +1464,13 @@ function _check_script_tag(&$var,$name='')
|
||||
static $preg = '/<\/?[^>]*\b(iframe|script|javascript|on(before)?(abort|blur|change|click|dblclick|error|focus|keydown|keypress|keyup|load|mousedown|mousemove|mouseout|mouseover|mouseup|reset|select|submit|unload))\b[^>]*>/i';
|
||||
if (preg_match($preg,$val))
|
||||
{
|
||||
// special handling for $_POST[json_data], to decend into it's decoded content, fixing json direct might break json syntax
|
||||
if ($name == '_POST' && $key == 'json_data' && ($json_data = json_decode($val, true)))
|
||||
{
|
||||
_check_script_tag($json_data, $name.'[json_data]');
|
||||
$_REQUEST[$key] = $var[$key] = json_encode($json_data);
|
||||
continue;
|
||||
}
|
||||
error_log(__FUNCTION__."(,$name) ${name}[$key] = ".$var[$key]);
|
||||
$GLOBALS['egw_unset_vars'][$name.'['.$key.']'] = $var[$key];
|
||||
// attempt to clean the thing
|
||||
|
Loading…
Reference in New Issue
Block a user