Changeset 866


Ignore:
Timestamp:
07/29/07 06:29:53 (7 years ago)
Author:
gogo
Message:

ticket:973 fix freezescript regexps

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/XinhaCore.js

    r863 r866  
    48724872   
    48734873  //prevent execution of JavaScript (Ticket #685) 
    4874   html = html.replace(/(<script[^>]*)(freezescript)/gi,"$1javascript"); 
     4874  html = html.replace(/(<script[^>]*((type=[\"\']text\/)|(language=[\"\'])))(freezescript)/gi,"$1javascript"); 
    48754875 
    48764876  // If in fullPage mode, strip the coreCSS 
     
    49154915  html = this.inwardSpecialReplacements(html); 
    49164916 
    4917   html = html.replace(/(<script[^>]*)(javascript)/gi,"$1freezescript"); 
     4917  html = html.replace(/(<script[^>]*((type=[\"\']text\/)|(language=[\"\'])))(javascript)/gi,"$1freezescript"); 
    49184918 
    49194919  // For IE's sake, make any URLs that are semi-absolute (="/....") to be 
Note: See TracChangeset for help on using the changeset viewer.