×

Notice

The forum is in read only mode.
Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1

TOPIC: Form validation and XSS protection

Form validation and XSS protection 8 years 8 months ago #33606

  • Kevin Chileong Lee
  • Kevin Chileong Lee's Avatar Topic Author
  • Offline
  • Fresh Boarder
  • Fresh Boarder
  • Posts: 4
  • Thank you received: 0
Dear Sir and Madam,

wer are interested in Matukio for Joomla 3. Unfortunately i can't find any informations about form field validations and XSS protection for the registration forms. Does your component have these? Is it possible to add custom validations for each form field?

I'm looking forward to hear from you.

Best regards,

Kevin Chileong Lee

Form validation and XSS protection 8 years 8 months ago #33607

  • Yves Hoppe
  • Yves Hoppe's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 3519
  • Karma: 71
  • Thank you received: 556
Hi Kevin,

the validation is done twice, once in JavaScript and once in PHP. And yes all Matukio forms do use the Joomla XSS protection (form.token).

You currently can't add custom validations, this is planed for a later version though.

Kind regards,
Yves

Form validation and XSS protection 8 years 8 months ago #33608

  • Kevin Chileong Lee
  • Kevin Chileong Lee's Avatar Topic Author
  • Offline
  • Fresh Boarder
  • Fresh Boarder
  • Posts: 4
  • Thank you received: 0
Hi Yves,

thank you for your quick response. Are the validations predefined or is at least possible to use regex validation?

Edit:
And i have one more question related to the XSS protection. Can we make sure that no script tags are able to fill in those forms and is it save that by viewing the forms in the backend that no scripts are being executed?

Best regards,
Kevin

Form validation and XSS protection 8 years 8 months ago #33609

  • Yves Hoppe
  • Yves Hoppe's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 3519
  • Karma: 71
  • Thank you received: 556
The validations are predefined.

Can we make sure that no script tags are able to fill in those forms and is it save that by viewing the forms in the backend that no scripts are being executed?


We strip and escape any html / scripts etc from the input before we save it. We are using Joomla JInput, which applies filter rules etc. and follow the joomla standards to prevent attacks of this kind.

Kind regards,
Yves

Form validation and XSS protection 8 years 8 months ago #33610

  • Kevin Chileong Lee
  • Kevin Chileong Lee's Avatar Topic Author
  • Offline
  • Fresh Boarder
  • Fresh Boarder
  • Posts: 4
  • Thank you received: 0
Thanks, that is enough information to me.
  • Page:
  • 1
Time to create page: 0.107 seconds