This directory holds supporting documentation for the OWASP Java HTML Sanitizer. Start with the project README for a short API example and links to the current Javadoc.
- Getting started explains how to obtain the library and identifies the main policy-building APIs.
- Using with Maven gives the dependency coordinates and JPMS module name.
- Why sanitize when you can validate? explains why the library returns normalized, sanitized output instead of declaring arbitrary input safe.
- Examples introduces the sample policies and their tests.
- Known public vulnerabilities lists published advisories and the first fixed versions.
- Attack review ground rules defines the scope for adversarial testing and links to the private reporting process.
- CVE-2011-4457 and CVE-2021-42575 provide historical notes for those issues.
Do not open a public issue for a suspected sanitizer bypass. Follow the repository's security policy so maintainers can coordinate a fix and disclosure.
The client-side template notes collect research on template-language syntax, including open questions and examples from other sanitizers.
The credits recognize project contributors. Release-by-release changes are recorded in the repository change log.