From 15903b4a2a100275a538b3b6bd64722a9c7a94d5 Mon Sep 17 00:00:00 2001 From: Michael Date: Fri, 19 Apr 2024 00:13:15 +0200 Subject: [PATCH 1/4] Improve a JSP example in JavaDocs. --- core/src/main/java/org/owasp/encoder/Encode.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/core/src/main/java/org/owasp/encoder/Encode.java b/core/src/main/java/org/owasp/encoder/Encode.java index 165635c..bbfdf53 100644 --- a/core/src/main/java/org/owasp/encoder/Encode.java +++ b/core/src/main/java/org/owasp/encoder/Encode.java @@ -243,7 +243,8 @@ public static void forHtmlContent(Writer out, String input) * * Example JSP Usage *
-     *     <div><%=Encode.forHtmlAttribute(unsafeData)%></div>
+     *     <div title="<%=Encode.forHtmlAttribute(unsafeData)%>">...</div>
+     *     <div title='<%=Encode.forHtmlAttribute(unsafeData)%>'>...</div>
      * 
* * From 0b581f8c4cdfde5b884b58718900a98f2285d7e8 Mon Sep 17 00:00:00 2001 From: Michael Date: Fri, 19 Apr 2024 00:27:09 +0200 Subject: [PATCH 2/4] Make JSP example in JavaDocs more concise. --- core/src/main/java/org/owasp/encoder/Encode.java | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/core/src/main/java/org/owasp/encoder/Encode.java b/core/src/main/java/org/owasp/encoder/Encode.java index bbfdf53..24bb520 100644 --- a/core/src/main/java/org/owasp/encoder/Encode.java +++ b/core/src/main/java/org/owasp/encoder/Encode.java @@ -243,8 +243,7 @@ public static void forHtmlContent(Writer out, String input) * * Example JSP Usage *
-     *     <div title="<%=Encode.forHtmlAttribute(unsafeData)%>">...</div>
-     *     <div title='<%=Encode.forHtmlAttribute(unsafeData)%>'>...</div>
+     *     <input value="<%=Encode.forHtml(unsafeData)%>" title='<%=Encode.forHtml(moreUnsafeData)%>' />
      * 
* *
From 604a78f9b926391bd3768ac4545a7c7396b90cca Mon Sep 17 00:00:00 2001 From: Michael Date: Fri, 19 Apr 2024 00:39:28 +0200 Subject: [PATCH 3/4] Be clearer about quotes in forHtmlAttribute docs. --- core/src/main/java/org/owasp/encoder/Encode.java | 2 ++ 1 file changed, 2 insertions(+) diff --git a/core/src/main/java/org/owasp/encoder/Encode.java b/core/src/main/java/org/owasp/encoder/Encode.java index 24bb520..2f66001 100644 --- a/core/src/main/java/org/owasp/encoder/Encode.java +++ b/core/src/main/java/org/owasp/encoder/Encode.java @@ -276,6 +276,8 @@ public static void forHtmlContent(Writer out, String input) * *

Additional Notes

*