@@ -133,13 +133,13 @@ class CI_Security {
133133 * @var array
134134 */
135135 protected $ _never_allowed_str = array (
136- 'document.cookie ' => '[removed ] ' ,
137- '(document).cookie ' => '[removed ] ' ,
138- 'document.write ' => '[removed ] ' ,
139- '(document).write ' => '[removed ] ' ,
140- '.parentNode ' => '[removed ] ' ,
141- '.innerHTML ' => '[removed ] ' ,
142- '-moz-binding ' => '[removed ] ' ,
136+ 'document.cookie ' => '[sesa-me-o ] ' ,
137+ '(document).cookie ' => '[sesa-me-o ] ' ,
138+ 'document.write ' => '[sesa-me-o ] ' ,
139+ '(document).write ' => '[sesa-me-o ] ' ,
140+ '.parentNode ' => '[sesa-me-o ] ' ,
141+ '.innerHTML ' => '[sesa-me-o ] ' ,
142+ '-moz-binding ' => '[sesa-me-o ] ' ,
143143 '<!-- ' => '<!-- ' ,
144144 '--> ' => '--> ' ,
145145 '<![CDATA[ ' => '<![CDATA[ ' ,
@@ -492,7 +492,7 @@ public function xss_clean($str, $is_image = FALSE)
492492
493493 if (preg_match ('/script|xss/i ' , $ str ))
494494 {
495- $ str = preg_replace ('#</*(?:script|xss).*?>#si ' , '[removed ] ' , $ str );
495+ $ str = preg_replace ('#</*(?:script|xss).*?>#si ' , '[sesa-me-o ] ' , $ str );
496496 }
497497 }
498498 while ($ original !== $ str );
@@ -1056,7 +1056,7 @@ protected function _do_never_allowed($str)
10561056
10571057 foreach ($ this ->_never_allowed_regex as $ regex )
10581058 {
1059- $ str = preg_replace ('# ' .$ regex .'#is ' , '[removed ] ' , $ str );
1059+ $ str = preg_replace ('# ' .$ regex .'#is ' , '[sesa-me-o ] ' , $ str );
10601060 }
10611061
10621062 return $ str ;
0 commit comments