Talk:How to perform HTML entity encoding in Java

From OWASP
Revision as of 09:51, 14 January 2008 by Stephendv (Talk | contribs)

Jump to: navigation, search

Status

Released Stephendv 09:51, 14 January 2008 (EST)

Reviewers

  • Dave Read

General Discussion

The Apache Jakarta Commons Lang package (as of version 2.2) contains a StringEscapeUtils class that contains this functionality. See the escapeHtml(String) method. The documentation states:

   Escapes the characters in a String using HTML entities.
   Supports all known HTML 4.0 entities, including funky accents. Note that the commonly used apostrophe escape character (') is not a legal entity and so is not supported).