@ThreadSafe @Immutable public final class PolicyFactory extends Object implements com.google.common.base.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy>
sanitize
method and a and
method to compose
policies.Modifier and Type | Method and Description |
---|---|
PolicyFactory |
and(PolicyFactory f)
Produces a factory that allows the union of the grants, and intersects
policies where they overlap on a particular granted attribute or element
name.
|
HtmlSanitizer.Policy |
apply(HtmlStreamEventReceiver out)
Produces a sanitizer that emits tokens to
out . |
<CTX> HtmlSanitizer.Policy |
apply(HtmlStreamEventReceiver out,
HtmlChangeListener<CTX> listener,
CTX context)
Produces a sanitizer that emits tokens to
out and that notifies
any listener of any dropped tags and attributes. |
String |
sanitize(String html)
A convenience function that sanitizes a string of HTML.
|
<CTX> String |
sanitize(String html,
HtmlChangeListener<CTX> listener,
CTX context)
A convenience function that sanitizes a string of HTML and reports
the names of rejected element and attributes to listener.
|
public HtmlSanitizer.Policy apply(@Nonnull HtmlStreamEventReceiver out)
out
.apply
in interface com.google.common.base.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy>
public <CTX> HtmlSanitizer.Policy apply(HtmlStreamEventReceiver out, @Nullable HtmlChangeListener<CTX> listener, @Nullable CTX context)
out
and that notifies
any listener
of any dropped tags and attributes.out
- a renderer that receives approved tokens only.listener
- if non-null, receives notifications of tags and attributes
that were rejected by the policy. This may tie into intrusion
detection systems.context
- if (listener != null)
then the context value passed
with notifications. This can be used to let the listener know from
which connection or request the questionable HTML was received.public String sanitize(@Nullable String html)
public <CTX> String sanitize(@Nullable String html, @Nullable HtmlChangeListener<CTX> listener, @Nullable CTX context)
html
- the string of HTML to sanitize.listener
- if non-null, receives notifications of tags and attributes
that were rejected by the policy. This may tie into intrusion
detection systems.context
- if (listener != null)
then the context value passed
with notifications. This can be used to let the listener know from
which connection or request the questionable HTML was received.public PolicyFactory and(PolicyFactory f)
Copyright © 2018 OWASP. All rights reserved.