regex 0.9.4

Python have been added. There is still some lacking functionality for showing the matches for all the functions in python but I’m getting there.

Changelog:

  • Added regex python

14 Responses to “regex 0.9.4”

  1. Thor Says:

    Heisann. å takk for hjelpen sist på diskusjon.no….
    Har det vært mulig å lagt til en knapp som escaper tekst(spesielt for pattern feltet).
    Det hadde mest sannsynlig spart litt tid.

  2. Lars Olav Torvik Says:

    Hei Thor.
    Godt forslag. Jeg skal ta det til vurdering til neste runde med oppdateringer av verktøyet. Må vurdere litt hvordan dette eventuelt skal implementeres på de forskjellige språkene.

    Kom gjerne med flere forslag til forbedringer!

  3. Thor Says:

    Høres bra ut ;)
    Litt stopp i utviklingen hos meg foreløbig, da jeg har en dagsjobb i tillegg til webkoding-hobby… men skal si fra hvis jeg finner på noen andre lure forslag :D

  4. Lars Olav Torvik Says:

    Kjenner til det at programmering på fritiden går veldig ofte i rykk og napp etter hvor mye tid og motivasjon man har. Jeg vet i hvertfall det er slik for meg :-)

    Tenkte litt på den ideen din men tror ikke det vil gå ann å implementere den fornuftig fordi umulig å vite når man skal escape og når man faktisk skal bruke spesial tegnet.

  5. Thor Says:

    ja skjønner.
    det var derfor jeg tenkte på en knapp dedikert til escaping. denne knappen gir brukeren en prompt der man kan skrive tekst og deretter plasseres teksten inn i pattern feltet ;) det var noe veldig enkelt jeg så for meg, fordi det er kun når man først går i gang å lager pattern at det trengs en hurtig escaping.

  6. Volcane Says:

    May I suggest you take this application down immediately and address the glaring security holes that is exposing your whole server’s contents to the world. I won’t mention details here but I am sure you can figure it out.

  7. Lars Olav Torvik Says:

    Thanks for your comment. I have installed a patch that hopefully solves this problem :-)

  8. Volcane Says:

    Have another go, its still VERY trivial.

  9. Mark Says:

    Yep, in firebug:

    document.getElementById(’pcre_modifiers_multiline’).value = ‘e’;

    Enable multiline mode and hack away! Filter your modifiers server-side and prevent it from happening at all.

  10. Mark Says:

    (Still, nice little tool though, for people who can’t yet process regex in their heads :-)

  11. Lars Olav Torvik Says:

    It seems I’m a bit naive when it comes to security. Not used to create applications like this. Usally just regular registrations forms etc that I need to make secure from injection attacks etc. I just created a tool I would like to use my self and decided to share :-)

    Mark: Thanks for the tips about the modifiers. The modifiers should now be filtered on the server.

    Volcane: I have done some other small modifications now but not sure if I have catched the security breach you saw or if it is the same as Mark commented. I would apreaciate it if you could send me a mail at meAlfaLarsolavtorvik.com with a concrete example I can test with.

    Atleast my app is getting some testing ;-)

  12. Lars Olav Torvik Says:

    Oh another small comment for Mark. There actually are a couple of people who can’t proccess regex in their heads :D

  13. Volcane Says:

    Thanks Lars, I think you’re app is great I have used several and reviewed several and once yours is sorted I think it will become my regex tester of choice, keep it up :)

    The basic rule is never rely on the client for input testing always do it server side and try to think out the box in terms of how people will use your app, def add some logging to see exactly what people are putting into your form so you can see what is being tried etc

  14. Mark Says:

    Yes, watching the logs will be fun :)

Leave a Reply