in src/main/java/org/apache/sling/xss/impl/XSSAPIImpl.java [209:223]
public String getValidJSToken(String token, String defaultValue) {
if (token != null && token.length() > 0) {
token = token.trim();
String q = token.substring(0, 1);
if (q.matches("['\"]") && token.endsWith(q)) {
String literal = token.substring(1, token.length() - 1);
return q + encodeForJSString(literal) + q;
} else if (token.matches("[0-9a-zA-Z_$][0-9a-zA-Z_$.]*")) {
return token;
}
}
// fall through to default value
return defaultValue;
}