Regular Expression validation
Regular Expression validation support regular expressions validation, blocks unsafe patterns, and explains how to simplify and test your regex rules safely.
When Zephr rejects a regular expression, you must review the pattern and replace or simplify it. Then save or publish the rule again.
Example of a blocked regular expression
The following regular expression requires processing for some inputs, so Zephr blocks it:
^(?:https?:\/\/)?(?:[a-z0-9-]+\.)*somereferrer\.com(?::\d+)?(?:[\/?#].*)?$
Use a simpler pattern that meets your requirements, and test the updated rule in a non-production environment before publishing it. Remember to test your pattern against a variety of inputs to ensure (for example) longer, more complex inputs do not expose a problem.
Use patterns that avoid unnecessary backtracking and that can be evaluated efficiently for the expected input.
Regex safety validation is a configuration-time safeguard based on static analysis. It is intended to identify potentially unsafe patterns before they are saved or published. Runtime handling of a problematic regular expression that already exists in a rule is outside the scope of this topic.