Nagesh Hebbar wrote:Also, I saw in some projects that the html encoding is done for even "<font colour" values. Please let me know which are all the fileds I need to encode.
Wouldn't it make more sense to ask about specific tags, attributes, etc. in the HTML forum?
In any case, I usually just make an S2 interceptor that does tag stripping, and I usually just use esapeHtml, but it depends on what I actually need to do.
*Which* tags is a completely separate issue, and more complex than you think, since you might also need to scrub even handler attributes and so on.