Skip to content
This repository was archived by the owner on Nov 18, 2025. It is now read-only.

Commit 413401e

Browse files
committed
👌 improve on security
1 parent 2ae0c64 commit 413401e

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

framework/core/Security.php

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -133,13 +133,13 @@ class CI_Security {
133133
* @var array
134134
*/
135135
protected $_never_allowed_str = array(
136-
'document.cookie' => '[removed]',
137-
'(document).cookie' => '[removed]',
138-
'document.write' => '[removed]',
139-
'(document).write' => '[removed]',
140-
'.parentNode' => '[removed]',
141-
'.innerHTML' => '[removed]',
142-
'-moz-binding' => '[removed]',
136+
'document.cookie' => '[sesa-me-o]',
137+
'(document).cookie' => '[sesa-me-o]',
138+
'document.write' => '[sesa-me-o]',
139+
'(document).write' => '[sesa-me-o]',
140+
'.parentNode' => '[sesa-me-o]',
141+
'.innerHTML' => '[sesa-me-o]',
142+
'-moz-binding' => '[sesa-me-o]',
143143
'<!--' => '&lt;!--',
144144
'-->' => '--&gt;',
145145
'<![CDATA[' => '&lt;![CDATA[',
@@ -492,7 +492,7 @@ public function xss_clean($str, $is_image = FALSE)
492492

493493
if (preg_match('/script|xss/i', $str))
494494
{
495-
$str = preg_replace('#</*(?:script|xss).*?>#si', '[removed]', $str);
495+
$str = preg_replace('#</*(?:script|xss).*?>#si', '[sesa-me-o]', $str);
496496
}
497497
}
498498
while ($original !== $str);
@@ -1056,7 +1056,7 @@ protected function _do_never_allowed($str)
10561056

10571057
foreach ($this->_never_allowed_regex as $regex)
10581058
{
1059-
$str = preg_replace('#'.$regex.'#is', '[removed]', $str);
1059+
$str = preg_replace('#'.$regex.'#is', '[sesa-me-o]', $str);
10601060
}
10611061

10621062
return $str;

0 commit comments

Comments
 (0)