Class HtmlEntityEncoder


  • public class HtmlEntityEncoder
    extends Object
    This class encodes HTML display content for preventing XSS.
    • Constructor Detail

      • HtmlEntityEncoder

        public HtmlEntityEncoder()
    • Method Detail

      • encodeXSS

        public static String encodeXSS​(Object obj)
      • encodeXSS

        public static String encodeXSS​(String s)
        Encode a) the following visible characters: " => 34, % => 37, & => 38, ' => 39, ( => 40, ) => 41, + => 43, ; => 59, < => 60, > => 62, b) ignore control characters c) ignore undefined characters