diff --git a/sectraining.md b/sectraining.md index 8eb86f5..af2d46e 100644 --- a/sectraining.md +++ b/sectraining.md @@ -19,16 +19,11 @@ To prevent non-HTML HTTP responses from embedding data, that might be dangerousl JavaScript frameworks (e.g., Angular, React) or server-side templating systems (e.g., Go Templates) have robust built-in protections against Reflected Cross-Site Scripting. #### Java -HTML Body
USER-CONTROLLED-DATA
`Encode.forHtml` - -HTML Attribute `Encode.forHtmlAttribute` - -URL Parameter Search `Encode.forUriComponent` - -CSS String
Selection
`Encode.forCssString` - -CSS URL
`Encode.forCssUrl` - -JavaScript Block `Encode.forJavaScriptBlock` - -JavaScript Variable `Encode.forJavaScriptVariable` +|---|---| +|HTML Body
USER-CONTROLLED-DATA
| `Encode.forHtml` | +|HTML Attribute `Encode.forHtmlAttribute`| +|URL Parameter Search |`Encode.forUriComponent`| +|CSS String
Selection
| `Encode.forCssString`| +|CSS URL
|`Encode.forCssUrl`| +|JavaScript Block | `Encode.forJavaScriptBlock`| +|JavaScript Variable |`Encode.forJavaScriptVariable`|