Forums

XSS Validation

EddieM 19 Oct, 2007
Hi,
I'm looking to add anti-XSS validation to some free text fields. So, I want to stripp out <> & some other characters. Unfortunately, the CE alpha-numeric validation is not for me, as it disallows spaces. I guess the regex used could be changed to allow spaces?

Perhaps, an enhancement would be to add a customisable validation field, where the user (ie form owner/developer) adds the characters that should be disallowed or stripped out before submission. CE then builds a regex using this input??

In the meantime, suggestions are welcome.

Thanks,

Eddie
Max_admin 20 Oct, 2007
Thanks Eddie, Indeed this is allowed with the validation script but not an implemented function with ChronoForms, I will add this to the todo list!

Cheers

Max
Max, ChronoForms developer
ChronoMyAdmin: Database administration within Joomla, no phpMyAdmin needed.
ChronoMails simplifies Joomla email: newsletters, logging, and custom templates.
This topic is locked and no more replies can be posted.