From 901746abcbb54ded3d39a977200ae7bf7db87664 Mon Sep 17 00:00:00 2001 From: Sander Hautvast Date: Mon, 5 Feb 2024 10:29:05 +0100 Subject: [PATCH] Update sectraining.md --- sectraining.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/sectraining.md b/sectraining.md index af2d46e..aff7f54 100644 --- a/sectraining.md +++ b/sectraining.md @@ -19,6 +19,8 @@ To prevent non-HTML HTTP responses from embedding data, that might be dangerousl JavaScript frameworks (e.g., Angular, React) or server-side templating systems (e.g., Go Templates) have robust built-in protections against Reflected Cross-Site Scripting. #### Java + +|type| java | |---|---| |HTML Body
USER-CONTROLLED-DATA
| `Encode.forHtml` | |HTML Attribute `Encode.forHtmlAttribute`|