0 голосов
/ 06 января 2020

Привет! Я использую библиотеку ow asp, чтобы исключить возможность межсайтового скриптинга. Есть еще некоторые теги и атрибуты, которые я хочу разрешить. Одним из тегов является td, а attribute - valign. Но это всегда терпит неудачу для valign атрибута со следующим сообщением. Тег td содержал атрибут, который мы не смогли обработать. Атрибут valign был отфильтрован, но тег все еще на месте. Значение атрибута было «top»

Ниже приведена антисамия xml конфигурации, которую я использовал.

    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
        <directive name="omitXmlDeclaration" value="true"/>
        <directive name="omitDoctypeDeclaration" value="true"/>
        <directive name="formatOutput" value="false"/>
        <directive name="embedStyleSheets" value="true"/>
        <directive name="maxStyleSheetImports" value="1"/>
        <directive name="connectionTimeout" value="1000"/>
        <directive name="preserveSpace" value="false"/>
        <directive name="useXHTML" value="true"/>
        <directive name="onUnknownTag" value="remove"/>
        <regexp name="colorName" value="(aqua|black|blue|fuchsia|gray|grey|green|lime|maroon|navy|olive|purple|red|silver|teal|white|yellow)"/>
        <regexp name="colorCode" value="(#([0-9a-fA-F]{6}|[0-9a-fA-F]{3}))"/>
        <regexp name="numberOrPercent" value="(\d)+(%{0,1})"/>
        <regexp name="htmlId" value="[a-zA-Z0-9-_]+"/>
        <regexp name="htmlTitle" value="[\p{L}\p{N}\s-_',:\[\]!\./\\\(\)]*"/>
        <regexp name="htmlClass" value="[a-zA-Z0-9\s,-_]+"/>
        <regexp name="onsiteURL" value="([\p{L}\p{N}\\\.\#@\$%\+&amp;;\-_~,\?=/!]+|\#(\w)+)"/>
        <regexp name="offsiteURL" value="(\s)*((ht|f)tp(s?)://|mailto:)[\p{L}\p{N}]+[\p{L}\p{N}\p{Zs}\.\#@\$%\+&amp;;:\-_~,\?=/!]*(\s)*"/>
        <regexp name="number" value="(-|\+)?([0-9]+(\.[0-9]+)?)"/> 
        <regexp name="anything" value=".*"/>
        <regexp name="valignValues" value="(baseline|bottom|middle|top)"/>
        <attribute name="id" description="The 'id' of any HTML attribute should not contain anything besides letters and numbers">
                <regexp name="htmlId"/>
        <attribute name="lang" description="The 'lang' attribute tells the browser what language the element's attribute values and content are written in">
                <regexp value="[a-zA-Z]{2,20}"/>
        <attribute name="colspan">
                <regexp name="number"/>
        <attribute name="title" description="The 'title' attribute provides text that shows up in a 'tooltip' when a user hovers their mouse over the element">
                <regexp name="htmlTitle"/>
        <attribute name="class" description="The 'class' of any HTML attribute is usually a single word, but it can also be a list of class names separated by spaces">
                <regexp name="htmlClass"/>
        <attribute name="href">
                <regexp name="onsiteURL"/>
                <regexp name="offsiteURL"/>
        <attribute name="target">
                <regexp name="htmlId"/>
        <attribute name="border">
                <regexp name="number"/>
        <attribute name="cellpadding">
                <regexp name="number"/>
        <attribute name="cellspacing">
                <regexp name="number"/>
        <attribute name="rowspan">
                <regexp name="number"/>
        <attribute name="background">
                <regexp name="onsiteURL"/>
        <attribute name="bgcolor">
                <regexp name="colorName"/>
                <regexp name="colorCode"/>
        <attribute name="width">
                <regexp name="numberOrPercent"/>
        <attribute name="height">
                <regexp name="numberOrPercent"/>
        <attribute name="align" description="The 'align' attribute of an HTML element is a direction word, like 'left', 'right' or 'center'">
                <literal value="center"/>
                <literal value="middle"/>
                <literal value="left"/>
                <literal value="right"/>
                <literal value="justify"/>
                <literal value="char"/>
           <attribute name="valign" description="The 'valign' attribute of an HTML attribute is a direction word, like 'baseline','bottom','middle' or 'top'">
                <literal value="baseline"/>
                <literal value="bottom"/>
                <literal value="middle"/>
                <literal value="top"/>

        <attribute name="size">
                <regexp name="number"/>
        <attribute name="autocomplete">
                <literal value="on"/>
                <literal value="off"/>
        <attribute name="rows">
                <regexp name="number"/>
        <attribute name="cols">
                <regexp name="number"/>
        <attribute name="onFocus" description="The 'onFocus' event is executed when the control associated with the tag gains focus"/>
        <attribute name="onBlur" description="The 'onBlur' event is executed when the control associated with the tag loses focus"/>
        <attribute name="onClick" description="The 'onClick' event is executed when the control associated with the tag is clicked"/>
        <attribute name="onDblClick" description="The 'onDblClick' event is executed when the control associated with the tag is clicked twice immediately"/>
        <attribute name="onMouseDown" description="The 'onMouseDown' event is executed when the control associated with the tag is clicked but not yet released"/>
        <attribute name="onMouseUp" description="The 'onMouseUp' event is executed when the control associated with the tag is clicked after the button is released"/>
        <attribute name="onMouseOver" description="The 'onMouseOver' event is executed when the user's mouse hovers over the control associated with the tag"/>
        <attribute name="scope" description="The 'scope' attribute defines what's covered by the header cells"/>
        <attribute name="title"/>
        <attribute name="lang"/>
        <tag xmlns:xsi="">g</tag>
        <tag xmlns:xsi="">grin</tag>
        <tag name="table" action="validate"/>
        <tag name="tbody" action="validate"/>
        <tag name="td" action="validate">
            <atrribute name="valign"/>
            <attribute name="colspan"/>
        <tag name="tr" action="validate">
        <atrribute name="valign"/>
        <tag name="hr" action="validate"/>
        <tag name="tt" action="validate"/>
        <tag name="a" action="validate"/>
        <tag name="b" action="validate"/>
        <tag name="blockquote" action="validate"/>
        <tag name="frameset" action="remove"/>
        <tag name="em" action="validate"/>
        <tag name="i" action="validate"/>
        <tag name="script" action="remove"/>
        <tag name="noframes" action="remove"/>
        <tag name="p" action="validate"/>
        <tag name="div" action="validate"/>
        <tag name="br" action="validate"/>
        <tag name="noscript" action="remove"/>
        <tag name="ul" action="validate"/>
        <tag name="iframe" action="remove"/>
        <tag name="ol" action="validate"/>
        <tag name="li" action="validate"/>
        <tag name="frame" action="remove"/>



            <literal value="br"/>
            <literal value="hr"/>
            <literal value="a"/>
            <literal value="img"/>
            <literal value="link"/>
            <literal value="iframe"/>
            <literal value="script"/>
            <literal value="object"/>
            <literal value="applet"/>
            <literal value="frame"/>
            <literal value="base"/>
            <literal value="param"/>
            <literal value="meta"/>
            <literal value="input"/>
            <literal value="textarea"/>
            <literal value="embed"/>
            <literal value="basefont"/>
            <literal value="col"/>
            <literal value="div"/>
            <literal value="EMPTY"/>