1const otpfieldSelectors = [ 2 'input[id*="mo_verify_otp"]', 3 'input[id*="mo_verify"]', 4 'input[id*="reg_vp_verification_phone"]', 5 'input[id*="mo_verify_code"]', 6 'input[id*="verify_field"]', 7 'input[name*=phone_verify]', 8 'input[name*=emai_verify]', 9 'input[id*=reg_verification_field]', 10 'input[id*=enter_otp-]', 11]; 12 13var $mo = (typeof window !== 'undefined' && window.$mo) ? window.$mo : jQuery; 14 15$mo(document).ready(function () { 16 const $otpFields = $mo(otpfieldSelectors.join(',')); 17 18 // Create safe regex pattern with proper validation 19 let inputPattern; 20 try { 21 if (typeof mootpalphanumeric !== 'undefined' && mootpalphanumeric.input_pattern) { 22 // Sanitize the regex pattern to prevent injection 23 const sanitizedPattern = $mo('<div/>').text(mootpalphanumeric.input_pattern).html(); 24 inputPattern = new RegExp(sanitizedPattern.replace(/^\/|\/[^\/]*$/g, ''), 'g'); 25 } else { 26 inputPattern = /[^a-zA-Z0-9]/g; 27 } 28 } catch (error) { 29 console.error('Invalid regex pattern:', error); 30 inputPattern = /[^a-zA-Z0-9]/g; // Fallback to safe default 31 } 32 33 $otpFields.on('input', function () { 34 const originalValue = this.value; 35 36 // Sanitize user input to prevent XSS 37 const sanitizedValue = $mo('<div/>').text(originalValue).html(); 38 const cleanedValue = sanitizedValue.replace(inputPattern, ''); 39 40 if (originalValue !== cleanedValue) { 41 // Safely update the input value 42 this.value = cleanedValue; 43 } 44 }); 45 46 $otpFields.on('paste', function (event) { 47 event.preventDefault(); 48 49 try { 50 const pastedData = event.originalEvent.clipboardData.getData('text'); 51 52 // Sanitize pasted data to prevent XSS 53 const sanitizedPastedData = $mo('<div/>').text(pastedData).html(); 54 const cleanedData = sanitizedPastedData.replace(inputPattern, ''); 55 56 const inputField = this; 57 const start = inputField.selectionStart; 58 const end = inputField.selectionEnd; 59 const currentValue = inputField.value; 60 61 // Safely construct new value 62 const newValue = currentValue.slice(0, start) + cleanedData + currentValue.slice(end); 63 64 // Update input value safely 65 inputField.value = newValue; 66 inputField.setSelectionRange(start + cleanedData.length, start + cleanedData.length); 67 } catch (error) { 68 console.error('Error handling paste event:', error); 69 // Fallback: prevent paste operation on error 70 event.preventDefault(); 71 } 72 }); 73});
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.