public interface

XhtmlCleaner

com.atlassian.confluence.content.render.xhtml.XhtmlCleaner
Known Indirect Subclasses

Class Overview

Responsible for cleaning supplied XHTML content into a form that is balanced and free of any insecure markup.

Summary

Nested Classes
class XhtmlCleaner.AppliedRuleDescription A description of a rule that was applied during the cleaning of content. 
class XhtmlCleaner.Result The complete results of a clean up operation. 
Public Methods
abstract XhtmlCleaner.Result clean(ContentEntityObject uncleanCeo)
Clean the supplied body content markup and make it safe from security concerns.
abstract String cleanQuietly(ContentEntityObject uncleanCeo)
Clean the specified body content markup and make it safe from security concerns with out reporting any clean up performed
abstract String cleanQuietly(String unclean, ConversionContext context)
Clean the specified String.
abstract String cleanStyleAttribute(String uncleanStyle)
Convert the supplied value of an HTML style attribute into a safe form if necessary.
abstract boolean isCleanUrlAttribute(String urlValue)
Test that the supplied value of a URL type attribute (such as href) is safe for output.

Public Methods

public abstract XhtmlCleaner.Result clean (ContentEntityObject uncleanCeo)

Clean the supplied body content markup and make it safe from security concerns.

Parameters
uncleanCeo a CEO containing the body content to be processed. The CEO is not modified, but the cleaned body content is returned.
Returns
  • a result encapsulating the cleaned version of the supplied body content XHTML as well as a description of rules applied.

public abstract String cleanQuietly (ContentEntityObject uncleanCeo)

Clean the specified body content markup and make it safe from security concerns with out reporting any clean up performed

Parameters
uncleanCeo a CEO containing the body content to be processed. The CEO is not modified, but the cleaned body content is returned.
Returns
  • a cleaned up version of the supplied body content

public abstract String cleanQuietly (String unclean, ConversionContext context)

Clean the specified String.

Parameters
unclean the String to be cleaned
context The ConversionContext that applies to the provided content.
Returns
  • a cleaned version of the supplied String

public abstract String cleanStyleAttribute (String uncleanStyle)

Convert the supplied value of an HTML style attribute into a safe form if necessary. If the result of the safety checking results in no properties remaining then it is possible that an empty String will be returned.

Parameters
uncleanStyle the style attribute value to be cleaned
Returns
  • a cleaned version of the supplied style attribute value..

public abstract boolean isCleanUrlAttribute (String urlValue)

Test that the supplied value of a URL type attribute (such as href) is safe for output.

Returns
  • true if this attribute value can be output, otherwise false.