Is it possible to "sandbox" html content within a JSP?

jksung used Ask the Experts™
I am trying to create a tool within my Spring MVC webapp where the JSP page takes in text from a user from a textbox, then displays the user text below the textbox with every non-UTF8 decode-able character highlighted in yellow (by taking in the user text as a string, and wrapping every non-UTF8 character with <span style='background:yellow'>(character)</span> and saving the result as form.userDataHighlighted), then display it in the webpage as such:

                                                <TD valign="top">

The problem is that the user may enter html content with CSS styling as such:

        <meta http-equiv=Content-Type content="text/plain; charset=utf-8">

                (some user defined styling)

and this can affect the styling of the main webpage (for example, change the background color of the main webpage).

Is there a way I can "sandbox" the user text within the JSP so that it cannot affect the main JSP styling (such as display it in some kind of frame)?  I have tried something like:

<table border="1">
<td style="width:500px;height:400px">
<iframe srcdoc=${form.userDataHighlighted} frameborder="0" style="width:100%;height:100%"></iframe>

and also:


but in both cases, the background color of the main page is still affected.  Is there a way I can display the user's text with the non-UTF8 characters highlighted without allowing the user content to affect the styling of the main page?
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
IT Business Systems Analyst / Software Developer
Top Expert 2015
Have you tried just escaping the user's input, something like this...

// Replace any < and > with their HTML entities, this should stop the browser from interpretting them as HTML but they should still output correctly
String userDataEscaped = form.userData.replaceAll("<", "&lt;").replaceAll(">", "&gt;");

// THEN, you can add in your <span style.. to highlight whatever you need
form.userDataHighlighted = highlightData(userDataEscaped);

Open in new window

As an aside, since most (all?) browsers will encode the users input AS UTF-8, how do you ever receive any NON UTF-8 characters?
Top Expert 2016

Escaping the user input (if they enter html, styled or otherwise) will leave you with tags on the page of course. Why not just strip out the tags? That will remove any styling too


Thank you!  This works perfectly for me.

To get the non-UTF characters (or the original string before the browser encodes it in utf8), we manually re-decode the string in the controller.
(String originalString = StringManipulation.decodeUTF8String(inputString);)
mccarlIT Business Systems Analyst / Software Developer
Top Expert 2015

You're welcome!

I was just thinking though, it would probably be beneficial to escape the & character as well. Like this...
String userDataEscaped = form.userData.replaceAll("&", "&amp;").replaceAll("<", "&lt;").replaceAll(">", "&gt;");

Open in new window

(Note the order of the above 'replace' operations are important, the '&' must be escaped first, otherwise it would break what the other two 'replace' are doing)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial