2 ms·
If you're able to input invalid URL's I guess I didn't test the regex thoroughly enough ;) I'll look into it. The prepending "http" is just a lazy hack to handl
by dtreacy 15y ago
If you're able to input invalid URL's I guess I didn't test the regex thoroughly enough ;)
I'll look into it.
The prepending "http" is just a lazy hack to handle the case where they enter "google.com" instead of "http://www.google.com http://www.google.com, which would fail the regex, but is a valid URL. This would be deprecated by improving the regex validation.
Keep in mind I threw this together in an afternoon.... But thanks for the critique ;)
- inakiabt 15y agoMaybe adding a simple "^" at the begining of the regex should be enough :) /^https?:\/\/([-\w\.]+)+(:\d+)?(\/([\w/_\.]*(\?\S+)?)?)?/ Otherwise, could be used for XSS. Like this url (http://naurls.me/39696e http://naurls.me/39696e): javascript:<script>alert('HELLO world');</script>http://naurl.me/