mirror of
https://github.com/Pathduck/gallery3.git
synced 2026-08-06 23:21:18 -04:00
Rename clean_js to js_string and have it return a complete JS string (with delimiters) instead of just the string contents.
Benefits: Using json_encode(), which is very robust. And as a user, it's clearer how to use this API compared to what it was before.
This commit is contained in:
@@ -188,7 +188,7 @@ class Xss_Security_Test extends Unit_Test_Case {
|
||||
if (self::_token_matches(array(T_DOUBLE_COLON, "::"), $tokens, $token_number + 1) &&
|
||||
self::_token_matches(array(T_STRING), $tokens, $token_number + 2) &&
|
||||
in_array($tokens[$token_number + 2][1],
|
||||
array("clean", "purify", "clean_js", "clean_attribute")) &&
|
||||
array("clean", "purify", "js_string", "clean_attribute")) &&
|
||||
self::_token_matches("(", $tokens, $token_number + 3)) {
|
||||
// Not checking for mark_safe(). We want such calls to be marked dirty (thus reviewed).
|
||||
|
||||
@@ -198,7 +198,7 @@ class Xss_Security_Test extends Unit_Test_Case {
|
||||
$token_number += 3;
|
||||
$token = $tokens[$token_number];
|
||||
|
||||
if ("clean_js" == $method) {
|
||||
if ("js_string" == $method) {
|
||||
$frame->is_safe_js(true);
|
||||
} else {
|
||||
$frame->is_safe_html(true);
|
||||
|
||||
Reference in New Issue
Block a user