From: moodler Date: Mon, 9 Jun 2003 05:54:14 +0000 (+0000) Subject: Better regular expression to catch javascript triggers X-Git-Url: http://git.mjollnir.org/gw?a=commitdiff_plain;h=f1c9d90fbb12100f0ce18bb57cfefb8c1a1f845b;p=moodle.git Better regular expression to catch javascript triggers --- diff --git a/lib/weblib.php b/lib/weblib.php index 7775512090..605cb8ed51 100644 --- a/lib/weblib.php +++ b/lib/weblib.php @@ -512,7 +512,7 @@ function clean_text($text, $format) { case FORMAT_WIKI: $text = strip_tags($text, $ALLOWED_TAGS); $text = str_ireplace("javascript:", " ", $text); // Remove javascript: label - $text = eregi_replace("([^a-z])on([a-z]+)=", " ", $text); // Remove javascript triggers + $text = eregi_replace("([^a-z])on([a-z]+)([[:space:]]*)=", " ", $text); // Remove javascript triggers return $text; case FORMAT_PLAIN: