interdire-scripts.yaml 544 B

1234567891011121314151617181920212223242526272829303132
  1. --- # Syntaxe des raccourcis SPIP, version 0.0.1
  2. #
  3. # Si on nomme une regle, elle devient surchargeable
  4. securite-asp:
  5. type: str
  6. match: "<%"
  7. replace: "&lt;%"
  8. securite-php:
  9. type: str
  10. match: "<?"
  11. replace: "&lt;?"
  12. securite-script-php:
  13. if_str: "<script"
  14. type: preg
  15. match: "/<(script\b[^>]+\blanguage\b[^\w>]+php\b)/UimsS"
  16. replace: "&lt;$1"
  17. securite-js:
  18. if_str: "<script"
  19. type: all
  20. replace: "echappe_js"
  21. is_callback: Y
  22. securite-base:
  23. if_str: "<base"
  24. type: preg
  25. match: "/<base\b/iS"
  26. replace: "&lt;base"