1/** 2 * Durcissement sécurité de tarteaucitron (build embarqué : version 20220322). 3 * 4 * Réplique à l'identique, par surcharge runtime, les correctifs officiels : 5 * - CVE-2023-3620 (corrigé upstream en 1.13.1, commit c4c2fcf) : 6 * getElemAttr passe désormais par tarteaucitron.fixSelfXSS. 7 * - CVE-2025-1467 (corrigé upstream en 1.17.0, commit 1249057) : 8 * getElemWidth / getElemHeight passent par getElemAttr (donc sanitisés). 9 * 10 * Aucun fichier vendor n'est modifié : ce script se contente de remplacer 11 * les 3 fonctions par les versions upstream corrigées. Il doit être chargé 12 * après tarteaucitron.js (inclusion en pied de page via TypoScript). 13 * Si tarteaucitron est absent de la page, il ne fait rien. 14 */ 15(function () { 16 "use strict"; 17 18 function harden() { 19 if (typeof tarteaucitron === "undefined" || typeof tarteaucitron.fixSelfXSS !== "function") { 20 return false; 21 } 22 if (tarteaucitron.__vdnHardened) { 23 return true; 24 } 25 26 /* Version upstream >= 1.13.1 de getElemAttr */ 27 tarteaucitron.getElemAttr = function (elem, attr) { 28 var attribute = elem.getAttribute("data-" + attr) || elem.getAttribute(attr); 29 if (typeof attribute === "string") { 30 return tarteaucitron.fixSelfXSS(attribute); 31 } 32 return ""; 33 }; 34 35 /* Version upstream >= 1.17.0 de getElemWidth / getElemHeight */ 36 tarteaucitron.getElemWidth = function (elem) { 37 return tarteaucitron.getElemAttr(elem, "width") || elem.clientWidth; 38 }; 39 tarteaucitron.getElemHeight = function (elem) { 40 return tarteaucitron.getElemAttr(elem, "height") || elem.clientHeight; 41 }; 42 43 tarteaucitron.__vdnHardened = true; 44 return true; 45 } 46 47 if (!harden()) { 48 document.addEventListener("DOMContentLoaded", harden); 49 } 50}());
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.