Skip to content

Commit

Permalink
update xss security
Browse files Browse the repository at this point in the history
  • Loading branch information
bobimicroweber committed Feb 14, 2022
1 parent 43efb2d commit 2876260
Show file tree
Hide file tree
Showing 3 changed files with 14 additions and 3 deletions.
5 changes: 3 additions & 2 deletions src/MicroweberPackages/CustomField/FieldsManager.php
Expand Up @@ -3,6 +3,7 @@
namespace MicroweberPackages\CustomField;

use MicroweberPackages\CustomField\Fields\Text;
use MicroweberPackages\Helper\HTMLClean;
use MicroweberPackages\Helper\XSSSecurity;
use function Matrix\trace;
use MicroweberPackages\CustomField\Events\CustomFieldWasDeleted;
Expand Down Expand Up @@ -306,8 +307,8 @@ public function save($fieldData)
return false;
}

$xssClean = new XSSSecurity();
$fieldData = $xssClean->clean($fieldData);
$xssClean = new HTMLClean();
$fieldData = $xssClean->cleanArray($fieldData);

if (isset($fieldData['copy_of']) and $fieldData['copy_of']) {

Expand Down
7 changes: 6 additions & 1 deletion src/MicroweberPackages/Helper/HTMLClean.php
Expand Up @@ -5,11 +5,16 @@
class HTMLClean
{
public function cleanArray($array) {

if (is_array($array)) {

$cleanedArray = [];
foreach ($array as $key=>$value) {
$cleanedArray[$key] = $this->clean($value);
if (is_array($value)) {
$cleanedArray[$key] = $this->cleanArray($value);
} else {
$cleanedArray[$key] = $this->clean($value);
}
}

return $cleanedArray;
Expand Down
5 changes: 5 additions & 0 deletions src/MicroweberPackages/Option/OptionManager.php
Expand Up @@ -14,6 +14,7 @@

use DB;
use Cache;
use MicroweberPackages\Helper\HTMLClean;
use MicroweberPackages\Option\Models\ModuleOption;
use MicroweberPackages\Option\Models\Option;
use MicroweberPackages\Option\Traits\ModuleOptionTrait;
Expand Down Expand Up @@ -349,6 +350,10 @@ public function save($data)
$data = parse_params($data);
}

$xssClean = new HTMLClean();
$data = $xssClean->cleanArray($data);


$this->clear_memory();
app()->option_repository->clearCache();

Expand Down

0 comments on commit 2876260

Please sign in to comment.