Encodes the inputString for safe output in the body of a HTML tag. The encoding in meant to mitigate Cross Site Scripting (XSS) attacks. This function can provide more protection from XSS than the HTMLEditFormat or XMLFormat functions do.

encodeForHTML(inputString [, canonicalize]) → returns string

encodeForHTML Argument Reference

inputString string

A string to encode

canonicalize boolean

When true runs the canonicalize function against the input before encoding. This argument is not supported on Lucee.

Pass in a tag and HTML encode the result.


Expected Result: &lt;test&gt;

