com.google.common.base.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy>, java.util.function.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy>@ThreadSafe @Immutable public final class PolicyFactory extends java.lang.Object implements com.google.common.base.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy>
sanitize
method and a and method to compose
policies.| Modifier and Type | Method | Description |
|---|---|---|
PolicyFactory |
and(PolicyFactory f) |
Produces a factory that allows the union of the grants, and intersects
policies where they overlap on a particular granted attribute or element
name.
|
HtmlSanitizer.Policy |
apply(HtmlStreamEventReceiver out) |
Produces a sanitizer that emits tokens to
out. |
<CTX> HtmlSanitizer.Policy |
apply(HtmlStreamEventReceiver out,
HtmlChangeListener<CTX> listener,
CTX context) |
Produces a sanitizer that emits tokens to
out and that notifies
any listener of any dropped tags and attributes. |
java.lang.String |
sanitize(java.lang.String html) |
A convenience function that sanitizes a string of HTML.
|
<CTX> java.lang.String |
sanitize(java.lang.String html,
HtmlChangeListener<CTX> listener,
CTX context) |
A convenience function that sanitizes a string of HTML and reports
the names of rejected element and attributes to listener.
|
public HtmlSanitizer.Policy apply(@Nonnull HtmlStreamEventReceiver out)
out.apply in interface com.google.common.base.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy>apply in interface java.util.function.Function<HtmlStreamEventReceiver,HtmlSanitizer.Policy>public <CTX> HtmlSanitizer.Policy apply(HtmlStreamEventReceiver out, @Nullable HtmlChangeListener<CTX> listener, @Nullable CTX context)
out and that notifies
any listener of any dropped tags and attributes.out - a renderer that receives approved tokens only.listener - if non-null, receives notifications of tags and attributes
that were rejected by the policy. This may tie into intrusion
detection systems.context - if (listener != null) then the context value passed
with notifications. This can be used to let the listener know from
which connection or request the questionable HTML was received.public java.lang.String sanitize(@Nullable
java.lang.String html)
public <CTX> java.lang.String sanitize(@Nullable
java.lang.String html,
@Nullable
HtmlChangeListener<CTX> listener,
@Nullable
CTX context)
html - the string of HTML to sanitize.listener - if non-null, receives notifications of tags and attributes
that were rejected by the policy. This may tie into intrusion
detection systems.context - if (listener != null) then the context value passed
with notifications. This can be used to let the listener know from
which connection or request the questionable HTML was received.public PolicyFactory and(PolicyFactory f)
Copyright © 2019 OWASP. All rights reserved.