Takes untrusted third-party HTML and returns HTML that is safe to embed, enforcing a configurable policy of elements, attributes, CSS and URLs. Used server-side across the Java ecosystem to stop cr...
Context-aware output encoding for HTML, attributes, JavaScript, CSS, URIs and XML, the primary defense against cross-site scripting in Java web applications. Dependency-free and high-performance; 7...