Cachet/config/security.php
2015-05-25 19:19:03 +01:00

26 lines
655 B
PHP

<?php
/*
* This file is part of Cachet.
*
* (c) Cachet HQ <support@cachethq.io>
*
* For the full copyright and license information, please view the LICENSE
* file that was distributed with this source code.
*/
return [
/*
|--------------------------------------------------------------------------
| Evil attributes
|--------------------------------------------------------------------------
|
| This defines the evil attributes and they will be always be removed from
| the input.
|
*/
'evil' => ['(?<!\w)on\w*', 'style', 'xmlns', 'formaction', 'form', 'xlink:href', 'FSCommand', 'seekSegmentTime'],
];