Class EcmaScriptSafeRegex

java.lang.Object
org.apache.struts2.components.EcmaScriptSafeRegex

public final class EcmaScriptSafeRegex extends Object
Decides whether a Java regular expression can be handed to a browser as an HTML5 pattern attribute without changing meaning.

This is an allowlist by design. A denylist of Java-only constructs would violate the never-false-reject rule the first time it missed one, because a missed construct becomes a pattern the browser interprets differently and the user cannot get past. Anything not provably common to both engines is rejected, and the field simply gets no client-side check.

Since:
7.4.0
  • Method Details

    • isSafe

      public static boolean isSafe(String regex)