1/*function sanitizeInput(input) { 2 // Remove dangerous characters and HTML tags 3 let value = input.value; 4 5 // Block script tags and javascript 6 if (value.match(/<script|javascript:|onerror|onload|onclick|onmouseover|vbscript:/gi)) { 7 logSecurityEvent('XSS attempt blocked', value, input.name); 8 input.value = ''; 9 input.style.borderColor = '#FF0000'; 10 alert('Security Alert: Potentially malicious content detected and removed.'); 11 return false; 12 } 13 14 // Remove HTML tags 15 value = value.replace(/<[^>]*>/g, ''); 16 17 // Remove dangerous characters 18 value = value.replace(/[<>\"']/g, ''); 19 20 // Limit to safe characters for names and companies 21 if (input.name === 'name' || input.name === 'demo_company') { 22 value = value.replace(/[^a-zA-Z0-9\s\.\-\_]/g, ''); 23 } 24 25 input.value = value; 26 input.style.borderColor = ''; 27 return true; 28}*/ 29function logSecurityEvent(event, data, field) { 30 // Log security events for monitoring 31 if (console && console.warn) { 32 console.warn('Security Event:', { 33 event: event, 34 field: field, 35 timestamp: new Date().toISOString(), 36 userAgent: navigator.userAgent, 37 data: data.substring(0, 100) // Only log first 100 chars 38 }); 39 } 40 41 // Send to server for logging (implement server-side logging) 42 try { 43 fetch('/page/log_security_event.php', { 44 method: 'POST', 45 headers: { 46 'Content-Type': 'application/json', 47 }, 48 body: JSON.stringify({ 49 event: event, 50 field: field, 51 data: data.substring(0, 100), 52 timestamp: new Date().toISOString(), 53 ip: '<?php echo $_SERVER["REMOTE_ADDR"]; ?>', 54 userAgent: navigator.userAgent 55 }) 56 }); 57 } catch (e) { 58 // Silently fail if logging doesn't work 59 } 60} 61 62 63function validateInputSecurity(value, fieldName) { 64 if (!value) return true; // Empty values are OK for optional fields 65 66 // Check for XSS patterns 67 const dangerousPatterns = [ 68 /<script/gi, 69 /javascript:/gi, 70 /onerror/gi, 71 /onload/gi, 72 /onclick/gi, 73 /onmouseover/gi, 74 /vbscript:/gi, 75 /<img.*src.*onerror/gi, 76 /<svg.*onload/gi, 77 /data:text\/html/gi, 78 /&#x/gi, 79 /&#[0-9]/gi 80 ]; 81 82 for (let pattern of dangerousPatterns) { 83 if (pattern.test(value)) { 84 logSecurityEvent('Dangerous pattern detected', value, fieldName); 85 alert('Security Alert: Your input contains potentially harmful content. Please revise and try again.'); 86 return false; 87 } 88 } 89 90 // Length validation 91 /*const maxLengths = { 92 'name': 100, 93 'email': 255, 94 'telephone': 20, 95 'postcode': 20, 96 'company': 150 97 }; 98 99 if (value.length > maxLengths[fieldName]) { 100 alert(`${fieldName} is too long. Maximum ${maxLengths[fieldName]} characters allowed.`); 101 return false; 102 }*/ 103 104 return true; 105 } 106 107 108 109 110 111function sanitizeInput($el) { 112 let value = $el.val(); 113 114 // block script/js keywords 115 if (/(\<script|javascript:|onerror|onload|onclick|onmouseover|vbscript:)/gi.test(value)) { 116 console.warn("XSS attempt blocked in field:", $el.attr("name"), value); 117 $el.val(''); 118 $el.css("border-color", "#FF0000"); 119 alert("Security Alert: Potentially malicious content detected and removed."); 120 return; 121 } 122 123 // remove html tags 124 value = value.replace(/<[^>]*>/g, ''); 125 126 // remove dangerous characters 127 value = value.replace(/[<>\"']/g, ''); 128 129 // restrict for name & company 130 if ($el.attr("name") === "name" || $el.attr("name") === "demo_company") { 131 value = value.replace(/[^a-zA-Z0-9\s.\-_]/g, ''); 132 } 133 134 // restrict for telephone (numeric only) 135 if ($el.attr("name") === "demo_telephone") { 136 value = value.replace(/[^0-9+]/g, ''); // allow digits and + 137 } 138 139 $el.val(value); 140 $el.css("border-color", ""); 141} 142 143 144// validate all fields dynamically and return errors array (empty if ok) 145function collectAndValidate($form, selector) { 146 const errors = []; 147 148 $form.find(selector).each(function () { 149 const $el = $(this); 150
151 // Skip disabled or explicitly skipped fields 152 if ($el.is(':disabled') || $el.data('skip-validate') === 1 || $el.data('skip-validate') === '1') { 153 return; // continue 154 } 155 156 const fieldKey = $el.data('field') || $el.attr('name') || $el.attr('id') || 'field'; 157 const value = $el.val() == null ? '' : String($el.val()); 158 159 // length enforcement (data-maxlength takes precedence) 160 const maxAttr = $el.data('maxlength') || $el.attr('maxlength'); 161 if (maxAttr) { 162 const maxLen = parseInt(maxAttr, 10); 163 if (!Number.isNaN(maxLen) && value.length > maxLen) { 164 errors.push({ field: fieldKey, selector: $el, reason: 'length', max: maxLen }); 165 $el.css('border-color', '#FF0000'); 166 return; 167 } 168 } 169 170 // optional custom pattern per field (data-pattern) 171 const pattern = $el.data('pattern'); 172 if (pattern) { 173 try { 174 const re = new RegExp(pattern); 175 if (!re.test(value)) { 176 errors.push({ field: fieldKey, selector: $el, reason: 'pattern' }); 177 $el.css('border-color', '#FF0000'); 178 return; 179 } 180 } catch (e) { 181 // invalid pattern - skip this check (or log) 182 console.warn('Invalid data-pattern for', fieldKey, e); 183 } 184 } 185 186 // call your existing function (single call per field) 187 const ok = validateInputSecurity(value, fieldKey); 188 if (!ok) { 189 errors.push({ field: fieldKey, selector: $el, reason: 'security' }); 190 $el.css('border-color', '#FF0000'); 191 } else { 192 // reset border if passed 193 $el.css('border-color', ''); 194 } 195 }); 196 197 return errors; 198} 199
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.