in src/main/java/org/apache/sling/xss/impl/HtmlSanitizer.java [45:58]
public SanitizedResult scan(String taintedHTML) {
StringBuilder sb = new StringBuilder(taintedHTML.length());
HtmlStreamEventReceiver out = HtmlStreamRenderer.create(sb, Handler.DO_NOTHING);
DynamicAttributesSanitizerPolicy dynamicPolicy = new DynamicAttributesSanitizerPolicy(
out,
policies,
textContainers,
customPolicy.getDynamicAttributesPolicyMap(),
customPolicy.getOnInvalidRemoveTagList());
org.owasp.html.HtmlSanitizer.sanitize(
taintedHTML, dynamicPolicy, customPolicy.getCssValidator().newStyleTagProcessor());
return new SanitizedResult(sb.toString(), dynamicPolicy.getNumberOfErrors());
}