Package com.adobe.acs.commons.xss
Class XSSFunctions
- java.lang.Object
-
- com.adobe.acs.commons.xss.XSSFunctions
-
@ProviderType public final class XSSFunctions extends Object
XSSAPI JSP Function wrappers.
-
-
Method Summary
All Methods Static Methods Concrete Methods Deprecated Methods Modifier and Type Method Description static CharSequenceencodeForHTML(com.adobe.granite.xss.XSSAPI xssAPI, String source)Deprecated.replaced byencodeForHTML(XSSAPI, String)Encode a string for HTML.static CharSequenceencodeForHTML(org.apache.sling.xss.XSSAPI xssAPI, String source)Encode a string for HTML.static CharSequenceencodeForHTMLAttr(com.adobe.granite.xss.XSSAPI xssAPI, String source)Deprecated.replaced byencodeForHTMLAttr(XSSAPI, String)Encode a string for an HTML attribute.static CharSequenceencodeForHTMLAttr(org.apache.sling.xss.XSSAPI xssAPI, String source)Encode a string for an HTML attribute.static CharSequenceencodeForJSString(com.adobe.granite.xss.XSSAPI xssAPI, String source)Deprecated.replaced byencodeForJSString(XSSAPI, String)Encode a string for an JavaScript string.static CharSequenceencodeForJSString(org.apache.sling.xss.XSSAPI xssAPI, String source)Encode a string for an JavaScript string.static CharSequencefilterHTML(com.adobe.granite.xss.XSSAPI xssAPI, String source)Deprecated.replaced byfilterHTML(XSSAPI, String)Filter a string for HTML.static CharSequencefilterHTML(org.apache.sling.xss.XSSAPI xssAPI, String source)Filter a string for HTML.static StringgetValidDimension(com.adobe.granite.xss.XSSAPI xssAPI, String dimension, String defaultValue)Deprecated.replaced bygetValidDimension(XSSAPI, String, String)Validate a string which should contain a dimension, returning a default value if the source is empty, can't be parsed, or contains XSS risks.static StringgetValidDimension(org.apache.sling.xss.XSSAPI xssAPI, String dimension, String defaultValue)Validate a string which should contain a dimension, returning a default value if the source is empty, can't be parsed, or contains XSS risks.static CharSequencegetValidHref(com.adobe.granite.xss.XSSAPI xssAPI, String source)Deprecated.replaced bygetValidHref(XSSAPI, String)Get a valid href.static CharSequencegetValidHref(org.apache.sling.xss.XSSAPI xssAPI, String source)Get a valid href.static IntegergetValidInteger(com.adobe.granite.xss.XSSAPI xssAPI, String integer, int defaultValue)Deprecated.replaced bygetValidInteger(XSSAPI, String, int)Validate a string which should contain an integer, returning a default value if the source is empty, can't be parsed, or contains XSS risks.static IntegergetValidInteger(org.apache.sling.xss.XSSAPI xssAPI, String integer, int defaultValue)Validate a string which should contain an integer, returning a default value if the source is empty, can't be parsed, or contains XSS risks.static StringgetValidJSToken(com.adobe.granite.xss.XSSAPI xssAPI, String token, String defaultValue)Deprecated.replaced bygetValidJSToken(XSSAPI, String, String)Validate a Javascript token.static StringgetValidJSToken(org.apache.sling.xss.XSSAPI xssAPI, String token, String defaultValue)Validate a Javascript token.
-
-
-
Method Detail
-
encodeForHTML
public static CharSequence encodeForHTML(org.apache.sling.xss.XSSAPI xssAPI, String source)
Encode a string for HTML.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
encodeForHTML
@Deprecated public static CharSequence encodeForHTML(com.adobe.granite.xss.XSSAPI xssAPI, String source)
Deprecated.replaced byencodeForHTML(XSSAPI, String)Encode a string for HTML.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
encodeForHTMLAttr
public static CharSequence encodeForHTMLAttr(org.apache.sling.xss.XSSAPI xssAPI, String source)
Encode a string for an HTML attribute.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
encodeForHTMLAttr
@Deprecated public static CharSequence encodeForHTMLAttr(com.adobe.granite.xss.XSSAPI xssAPI, String source)
Deprecated.replaced byencodeForHTMLAttr(XSSAPI, String)Encode a string for an HTML attribute.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
encodeForJSString
public static CharSequence encodeForJSString(org.apache.sling.xss.XSSAPI xssAPI, String source)
Encode a string for an JavaScript string.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
encodeForJSString
@Deprecated public static CharSequence encodeForJSString(com.adobe.granite.xss.XSSAPI xssAPI, String source)
Deprecated.replaced byencodeForJSString(XSSAPI, String)Encode a string for an JavaScript string.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
filterHTML
public static CharSequence filterHTML(org.apache.sling.xss.XSSAPI xssAPI, String source)
Filter a string for HTML.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
filterHTML
@Deprecated public static CharSequence filterHTML(com.adobe.granite.xss.XSSAPI xssAPI, String source)
Deprecated.replaced byfilterHTML(XSSAPI, String)Filter a string for HTML.- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
getValidHref
public static CharSequence getValidHref(org.apache.sling.xss.XSSAPI xssAPI, String source)
Get a valid href. This does not use the standard XSS API due to a bug impacting CQ 5.6.1 (and earlier). Internal bug reference: GRANITE-4193- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
getValidHref
@Deprecated public static CharSequence getValidHref(com.adobe.granite.xss.XSSAPI xssAPI, String source)
Deprecated.replaced bygetValidHref(XSSAPI, String)Get a valid href. This does not use the standard XSS API due to a bug impacting CQ 5.6.1 (and earlier). Internal bug reference: GRANITE-4193- Parameters:
xssAPI- the XSSAPIsource- the source string- Returns:
- the encoded string
-
getValidDimension
public static String getValidDimension(org.apache.sling.xss.XSSAPI xssAPI, String dimension, String defaultValue)
Validate a string which should contain a dimension, returning a default value if the source is empty, can't be parsed, or contains XSS risks. Allows integer dimensions and the keyword "auto".- Parameters:
xssAPI- the XSSAPIdimension- the source dimensiondefaultValue- a default value if the source can't be used- Returns:
- a sanitized dimension
-
getValidDimension
@Deprecated public static String getValidDimension(com.adobe.granite.xss.XSSAPI xssAPI, String dimension, String defaultValue)
Deprecated.replaced bygetValidDimension(XSSAPI, String, String)Validate a string which should contain a dimension, returning a default value if the source is empty, can't be parsed, or contains XSS risks. Allows integer dimensions and the keyword "auto".- Parameters:
xssAPI- the XSSAPIdimension- the source dimensiondefaultValue- a default value if the source can't be used- Returns:
- a sanitized dimension
-
getValidInteger
public static Integer getValidInteger(org.apache.sling.xss.XSSAPI xssAPI, String integer, int defaultValue)
Validate a string which should contain an integer, returning a default value if the source is empty, can't be parsed, or contains XSS risks.- Parameters:
xssAPI- the XSSAPIinteger- the source integerdefaultValue- a default value if the source can't be used- Returns:
- a sanitized integer
-
getValidInteger
@Deprecated public static Integer getValidInteger(com.adobe.granite.xss.XSSAPI xssAPI, String integer, int defaultValue)
Deprecated.replaced bygetValidInteger(XSSAPI, String, int)Validate a string which should contain an integer, returning a default value if the source is empty, can't be parsed, or contains XSS risks.- Parameters:
xssAPI- the XSSAPIinteger- the source integerdefaultValue- a default value if the source can't be used- Returns:
- a sanitized integer
-
getValidJSToken
public static String getValidJSToken(org.apache.sling.xss.XSSAPI xssAPI, String token, String defaultValue)
Validate a Javascript token. The value must be either a single identifier, a literal number, or a literal string.- Parameters:
xssAPI- the XSSAPItoken- the source tokendefaultValue- a default value to use if the source doesn't meet validity constraints.- Returns:
- a string containing a single identifier, a literal number, or a literal string token
-
getValidJSToken
@Deprecated public static String getValidJSToken(com.adobe.granite.xss.XSSAPI xssAPI, String token, String defaultValue)
Deprecated.replaced bygetValidJSToken(XSSAPI, String, String)Validate a Javascript token. The value must be either a single identifier, a literal number, or a literal string.- Parameters:
xssAPI- the XSSAPItoken- the source tokendefaultValue- a default value to use if the source doesn't meet validity constraints.- Returns:
- a string containing a single identifier, a literal number, or a literal string token
-
-