import { createSignal, Show } from "solid-js"; interface CommentFormData { content: string; } interface ValidationErrors { content?: string; } interface CommentFormProps { onSubmit: (data: CommentFormData) => void; isReply?: boolean; onCancel?: () => void; user?: { name: string; email: string; avatar?: string; }; } const MAX_MESSAGE_LENGTH = 2000; const MIN_MESSAGE_LENGTH = 10; const DANGEROUS_PATTERNS = [ /)<[^<]*)*<\/script>/gi, /javascript:/gi, /on\w+\s*=/gi, /)<[^<]*)*<\/iframe>/gi, /)<[^<]*)*<\/object>/gi, //gi, /data:text\/html/gi, /expression\s*\(/gi, /url\s*\(\s*['"]*\s*javascript:/gi, ]; export default function CommentForm(props: CommentFormProps) { const [content, setContent] = createSignal(""); const [errors, setErrors] = createSignal({}); const [touched, setTouched] = createSignal<{ [key: string]: boolean }>({}); const sanitizeInput = (input: string): string => { return input .replace(/[<>]/g, "") .replace(/"/g, """) .replace(/'/g, "'") .replace(/&/g, "&"); }; const containsDangerousContent = (input: string): boolean => { return DANGEROUS_PATTERNS.some((pattern) => pattern.test(input)); }; const validateContent = (value: string): string | undefined => { const trimmed = value.trim(); if (!trimmed) return "Комментарий обязателен"; if (trimmed.length < MIN_MESSAGE_LENGTH) return `Минимум ${MIN_MESSAGE_LENGTH} символов`; if (trimmed.length > MAX_MESSAGE_LENGTH) return `Максимум ${MAX_MESSAGE_LENGTH} символов`; if (containsDangerousContent(trimmed)) return "Обнаружен опасный контент"; return undefined; }; const handleContentChange = (e: Event) => { const target = e.target as HTMLTextAreaElement; let value = target.value; if (containsDangerousContent(value)) { DANGEROUS_PATTERNS.forEach((pattern) => { value = value.replace(pattern, ""); }); } if (value.length > MAX_MESSAGE_LENGTH) { value = value.slice(0, MAX_MESSAGE_LENGTH); } setContent(value); if (touched().content) { setErrors((prev) => ({ ...prev, content: validateContent(value) })); } }; const validateForm = (): boolean => { const contentError = validateContent(content()); setErrors({ content: contentError }); setTouched({ content: true }); return !contentError; }; const handleSubmit = (e: Event) => { e.preventDefault(); if (!validateForm()) return; props.onSubmit({ content: sanitizeInput(content().trim()), }); setContent(""); setErrors({}); setTouched({}); }; const handleBlur = () => { setTouched((prev) => ({ ...prev, content: true })); setErrors((prev) => ({ ...prev, content: validateContent(content()) })); }; const isValid = () => { return !errors().content && content().trim(); }; return (

{props.isReply ? "Написать ответ" : "Оставить комментарий"}