HTML - Escape / Sanitizer


A sanitizer is a program that will:

This is to avoid script injection and should be used on the server side (ie not client) to validate/transform all inputs.

Example of sanitizing

<img src=x onerror=alert(1)//>
<img src="x">
Delete the onload and makes the svg XHTML conform
Delete the iframe
Delete the script node
Make the HTML conform
<UL><li><A HREF=//>click</UL>
<ul><li><a href="//">click</a></li></ul>



