Changeset 11

Show
Ignore:
Timestamp:
02/07/06 17:27:49 (4 years ago)
Author:
bradfitz
Message:

don't allow backslash+hex anywhere. avoid us having to decode it,
then check it.

Files:
1 modified

Legend:

Unmodified
Added
Removed
  • trunk/lib/CSS/Cleaner.pm

    r10 r11  
    5050    $reduced =~ s/&\#x(\w+);?/chr(hex($1))/eg; 
    5151    $reduced =~ s/\s+//g; 
     52 
     53    if ($reduced =~ m!\\[a-f0-9]!i) { 
     54        $$ref = "/* suspect CSS: backslash hex */"; 
     55        return; 
     56    } 
     57 
    5258    $reduced =~ s/\\//g; 
    5359