0
votes

In our application, in landing page we show a scrolling message, which is entered in a admin screen and stored in DB and shown to other external users when they login (like "the site will be down for maintenance.. etc). The message is entered with html tags to change color and text size.

During security testing this process failed as a java script was introduced and it runs on landing page.

We are advised to use ESAPI libraries. Used many Encoder methods. All those are encoding all the tags. I want to allow few html tags and encode everything else.

In some other forums, it is mentioned to use HTML sanitizer. What is the right way to do please..

1

1 Answers

0
votes

I would not recommend any application that wasn't already using ESAPI to adopt it. ESAPI Java lost its flagship status in 2014 for lack of active development. That link is to one of the lead developer's blog. It does have one thing that no other security library has, to my knowledge: detection for mixed and multiple encoding. So weigh the risks.

IF you need output encoding, use the esapi encoder project. Every time you output to a new context (HTML, Javascript, etc.) you'll want to escape data.

It sounds however like your requirement is to be able to permit user-supplied HTML/javascript. This is where you would want to use an HTML sanitizer.

One fairly easy solution would be the JSOUP library. Now, just don't use it for input validation of markdown. It's designed to "fix" invalid HTML and for input validation you want your input to be unchanged.