Class Escape

java.lang.Object
org.apache.tomcat.util.security.Escape

public class Escape extends Object
Provides utility methods to escape content for different contexts. It is critical that the escaping used is correct for the context in which the data is to be used.
  • Method Details

    • htmlElementContent

      public static String htmlElementContent(String content)
      Escape content for use in HTML. This escaping is suitable for the following uses:
      • Element content when the escaped data will be placed directly inside tags such as <p>, <td> etc.
      • Attribute values when the attribute value is quoted with " or '.
      Parameters:
      content - The content to escape
      Returns:
      The escaped content or null if the content was null
    • htmlElementContent

      public static String htmlElementContent(Object obj)
      Convert the object to a string via Object.toString() and HTML escape the resulting string for use in HTML content.
      Parameters:
      obj - The object to convert to String and then escape
      Returns:
      The escaped content or "?" if obj is null
    • xml

      public static String xml(String content)
      Escape content for use in XML.
      Parameters:
      content - The content to escape
      Returns:
      The escaped content or null if the content was null
    • xml

      public static String xml(String ifNull, String content)
      Escape content for use in XML.
      Parameters:
      ifNull - The value to return if content is null
      content - The content to escape
      Returns:
      The escaped content or the value of ifNull if the content was null
    • xml

      public static String xml(String ifNull, boolean escapeCRLF, String content)
      Escape content for use in XML.
      Parameters:
      ifNull - The value to return if content is null
      escapeCRLF - Should CR and LF also be escaped?
      content - The content to escape
      Returns:
      The escaped content or the value of ifNull if the content was null