Class SecureFilter

SecureFilter contains many methods for manipulating untrusted data Strings into RFC-Compliant Strings for a given context by removing “bad” data from the untrusted data.

Constructor Summary 

This class does not have a constructor, so you cannot create it directly.

Method Summary 

MethodDescription
static forHtmlContent(String)

Filters illegal characters from a given input for use in a general HTML context.

static forHtmlInDoubleQuoteAttribute(String)

Filters illegal characters from a given input for use in an HTML Attribute guarded by a double quote.

static forHtmlInSingleQuoteAttribute(String)

Filters illegal characters from a given input for use in an HTML Attribute guarded by a single quote.

static forHtmlUnquotedAttribute(String)

Filters illegal characters from a given input for use in an HTML Attribute left unguarded.

static forJSONValue(String)

Filters illegal characters from a given input for use in a JSON Object Value to prevent escaping into a trusted context.

static forJavaScriptInAttribute(String)

Filters illegal characters from a given input for use in JavaScript inside an HTML attribute.

static forJavaScriptInBlock(String)

Filters illegal characters from a given input for use in JavaScript inside an HTML block.

static forJavaScriptInHTML(String)

Filters illegal characters from a given input for use in JavaScript inside an HTML context.

static forJavaScriptInSource(String)

Filters illegal characters from a given input for use in JavaScript inside a JavaScript source file.

static forUriComponent(String)

Filters illegal characters from a given input for use as a component of a URI.

static forUriComponentStrict(String)

Filters illegal characters from a given input for use as a component of a URI.

static forXmlCommentContent(String)

Filters illegal characters from a given input for use in an XML comments.

static forXmlContent(String)

Filters illegal characters from a given input for use in a general XML context.

static forXmlInDoubleQuoteAttribute(String)

Filters illegal characters from a given input for use in an XML attribute guarded by a double quote.

static forXmlInSingleQuoteAttribute(String)

Filters illegal characters from a given input for use in an XML attribute guarded by a single quote.

Methods inherited from class Object 

assign, create, create, defineProperties, defineProperty, entries, freeze, fromEntries, getOwnPropertyDescriptor, getOwnPropertyNames, getOwnPropertySymbols, getPrototypeOf, hasOwnProperty, is, isExtensible, isFrozen, isPrototypeOf, isSealed, keys, preventExtensions, propertyIsEnumerable, seal, setPrototypeOf, toLocaleString, toString, valueOf, values

Method Details 

forHtmlContent(String) 

static forHtmlContent(input: String): String

Filters illegal characters from a given input for use in a general HTML context. E.g. text content and text attributes. This method takes the UNION of allowed characters among all contexts, so may be more imprecise that the more specific contexts. Generally, this method is preferred unless you specifically understand the context in which untrusted data will be output.

Example Usage:

1<div>${SecureFilter.forHtmlContent(unsafeData)}</div>
2
3<input value="${SecureFilter.forHtmlContent(unsafeData)}" />

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forHtmlInDoubleQuoteAttribute(String) 

static forHtmlInDoubleQuoteAttribute(input: String): String

Filters illegal characters from a given input for use in an HTML Attribute guarded by a double quote. This method is preferred if you understand exactly how the output of this will be used in the HTML document.

Example Usage:

1<div id="${SecureFilter.forHtmlInDoubleQuoteAttribute(unsafeData)}"></div>

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forHtmlInSingleQuoteAttribute(String) 

static forHtmlInSingleQuoteAttribute(input: String): String

Filters illegal characters from a given input for use in an HTML Attribute guarded by a single quote. This method is preferred if you understand exactly how the output of this will be used in the HTML document.

Example Usage:

1<div id='${SecureFilter.forHtmlInSingleQuoteAttribute(unsafeData)}'></div>

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filterd, if necessary

Returns:

  • a properly filtered string for the given input

forHtmlUnquotedAttribute(String) 

static forHtmlUnquotedAttribute(input: String): String

Filters illegal characters from a given input for use in an HTML Attribute left unguarded. This method is preferred if you understand exactly how the output of this will be used in the HTML document.

Example Usage:

1<div id=${SecureFilter.forHtmlUnquotedAttribute(unsafeData)}></div>

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forJSONValue(String) 

static forJSONValue(input: String): String

Filters illegal characters from a given input for use in a JSON Object Value to prevent escaping into a trusted context.

Example Usage:

1var json = {"trusted_data" : SecureFilter.forJSONValue(unsafeData)};
2return JSON.stringify(json);

Flow:

  • Allow AlphaNumerics
  • Remove all other characters

Parameters:

  • input - ed input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forJavaScriptInAttribute(String) 

static forJavaScriptInAttribute(input: String): String

Filters illegal characters from a given input for use in JavaScript inside an HTML attribute. This method is preferred if you understand exactly how the output of the will be used in the page

Example Usage:

1<button onclick="alert('${SecureFilter.forJavaScriptInAttribute(unsafeData)}');">

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forJavaScriptInBlock(String) 

static forJavaScriptInBlock(input: String): String

Filters illegal characters from a given input for use in JavaScript inside an HTML block. This method is preferred if you understand exactly how the output of the will be used in the page

Example Usage:

1<script type="text/javascript">
2    var data = "${SecureFilter.forJavaScriptInBlock(unsafeData)}";
3</script>

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forJavaScriptInHTML(String) 

static forJavaScriptInHTML(input: String): String

Filters illegal characters from a given input for use in JavaScript inside an HTML context. This method takes the UNION of allowed characters among the other contexts, so may be more imprecise that the more specific contexts. Generally, this method is preferred unless you specifically understand the context in which untrusted data will be output.

Example Usage:

1<script type="text/javascript">
2    var data = "${SecureFilter.forJavaScriptInHTML(unsafeData)}";
3</script>
4
5<button onclick="alert('${SecureFilter.forJavaScriptInHTML(unsafeData)}');">

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forJavaScriptInSource(String) 

static forJavaScriptInSource(input: String): String

Filters illegal characters from a given input for use in JavaScript inside a JavaScript source file. This method is preferred if you understand exactly how the output of the will be used in the page

Example Usage:

1<...inside foobar.js...>
2var data = "${SecureFilter.forJavaScriptInSource(unsafeData)}";

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forUriComponent(String) 

static forUriComponent(input: String): String

Filters illegal characters from a given input for use as a component of a URI. This is equivalent to javascript's filterURIComponent and does a realistic job of encoding.

Example Usage:

1<a href="http://host.com?value=${SecureFilter.forUriComponent(unsafeData)}"/>

Allows:

1A-Z, a-z, 0-9, -, _, ., ~, !, *, ', (, )

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forUriComponentStrict(String) 

static forUriComponentStrict(input: String): String

Filters illegal characters from a given input for use as a component of a URI. This is a strict filter and fully complies with RFC3986.

Example Usage:

1<a href="http://host.com?value=${SecureFilter.forUriComponentStrict(unsafeData)}"/>

Allows:

1A-Z, a-z, 0-9, -, _, ., ~

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forXmlCommentContent(String) 

static forXmlCommentContent(input: String): String

Filters illegal characters from a given input for use in an XML comments. This method is preferred if you understand the context in which untrusted data will be output.

Note: It is recommended that you use a real parser, as this method can be misused, but is left here if a parser is unavailable to you

Example Usage:

1<!-- ${SecureFilter.forXmlCommentContent(unsafeData)} -->

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forXmlContent(String) 

static forXmlContent(input: String): String

Filters illegal characters from a given input for use in a general XML context. E.g. text content and text attributes. This method takes the UNION of allowed characters between the other contexts, so may be more imprecise that the more specific contexts. Generally, this method is preferred unless you specifically understand the context in which untrusted data will be output.

Note: It is recommended that you use a real parser, as this method can be misused, but is left here if a parser is unavailable to you

Example Usage:

1<foo>${SecureFilter.forXmlContent(unsafeData)}</foo>
2
3<bar attr="${SecureFilter.forXmlContent(unsafeData)}"></bar>

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forXmlInDoubleQuoteAttribute(String) 

static forXmlInDoubleQuoteAttribute(input: String): String

Filters illegal characters from a given input for use in an XML attribute guarded by a double quote. This method is preferred if you understand the context in which untrusted data will be output.

Note: It is recommended that you use a real parser, as this method can be misused, but is left here if a parser is unavailable to you

Example Usage:

1<bar attr="${SecureFilter.forXmlInDoubleQuoteAttribute(unsafeData)}"></bar>

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

forXmlInSingleQuoteAttribute(String) 

static forXmlInSingleQuoteAttribute(input: String): String

Filters illegal characters from a given input for use in an XML attribute guarded by a single quote. This method is preferred if you understand the context in which untrusted data will be output.

Note: It is recommended that you use a real parser, as this method can be misused, but is left here if a parser is unavailable to you

Example Usage:

1<bar attr='${SecureFilter.forXmlInSingleQuoteAttribute(unsafeData)}'></bar>

Flow:

  • Allow AlphaNumerics and some Special characters
  • Remove all other characters

Parameters:

  • input - untrusted input to be filtered, if necessary

Returns:

  • a properly filtered string for the given input

DID THIS ARTICLE SOLVE YOUR ISSUE?
Let us know so we can improve!