/* * eGov suite of products aim to improve the internal efficiency,transparency, * accountability and the service delivery of the government organizations. * * Copyright (C) <2015> eGovernments Foundation * * The updated version of eGov suite of products as by eGovernments Foundation * is available at http://www.egovernments.org * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation, either version 3 of the License, or * any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program. If not, see http://www.gnu.org/licenses/ or * http://www.gnu.org/licenses/gpl.html . * * In addition to the terms of the GPL license to be adhered to in using this * program, the following additional terms are to be complied with: * * 1) All versions of this program, verbatim or modified must carry this * Legal Notice. * * 2) Any misrepresentation of the origin of the material is prohibited. It * is required that all modified versions of this material be marked in * reasonable ways as different from the original version. * * 3) This license does not grant any rights to any user of the program * with regards to rights under trademark law for use of the trade names * or trademarks of eGovernments Foundation. * * In case of any queries, you can reach eGovernments Foundation at contact@egovernments.org. */ package org.egov.infra.security.utils; import org.egov.infra.exception.ApplicationRuntimeException; import org.owasp.validator.html.AntiSamy; import org.owasp.validator.html.CleanResults; import org.owasp.validator.html.Policy; import org.owasp.validator.html.PolicyException; import org.slf4j.Logger; import org.slf4j.LoggerFactory; import static org.apache.commons.lang.StringUtils.isBlank; /** * VirtualSanitizer.java This class used to sanitise user input from possible XSS attacks. **/ public final class VirtualSanitizer { private static final Logger LOG = LoggerFactory.getLogger(VirtualSanitizer.class); private static Policy policy; private static AntiSamy antiSamy; private static AntiSamy getAntiSamy() throws PolicyException { if (antiSamy == null) { policy = getPolicy("antisamy-myspace-1.4.3.xml"); antiSamy = new AntiSamy(); } return antiSamy; } private static Policy getPolicy(final String name) throws PolicyException { final Policy policy = Policy.getInstance(VirtualSanitizer.class.getResource(name)); return policy; } public static String sanitize(final String input) { try { if (isBlank(input)) { return input; } final CleanResults cr = getAntiSamy().scan(input, policy); if (cr.getErrorMessages().size() > 0) { LOG.error(cr.getErrorMessages().toString()); throw new ApplicationRuntimeException("Found security threat in user input : " + cr.getErrorMessages()); } return input; } catch (final Exception e) { LOG.error(e.getMessage()); throw new ApplicationRuntimeException("Error occurred while validating inputs", e); } } }