Solution
Use the jsoup HTML Cleaner
with a configuration specified by a Whitelist
.
String unsafe =
"<p><a href='http://example.com/' onclick='stealCookies()'>Link</a></p>";
String safe = Jsoup.clean(unsafe, Whitelist.basic());
// now: <p><a href="http://example.com/" rel="nofollow">Link</a></p
Read full article from Prevent cross site scripting with jsoup
No comments:
Post a Comment