Safe html in java

故事扮演 提交于 2019-12-02 01:21:46

Google caja is a tool for making third party HTML, CSS and JavaScript safe to embed in your website.

OWASP AntiSamy is a project for just that. If you need users to be able to submit structured text, look at markdown (imho a lot better than BBCode).

Playframework 2 already offers a solution.

the @Html() function filters bad html, which is really nice.

I really love play2

You might want to just escape all html. If you want to have users be able to use basic html tags like <b> or <i> then you could just replace them with [b] and [i] (if your forum/whatever you're creating can use bbcode), then just replace all "<" and ">" with "&lt;" and "&gt;".

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!