Sanitize Html
Audience:
Low-code EngineersSkill Prerequisites:
HTML,Tokens
Cleans a piece of HTML and stores the result in a token. It can remove tags, remove tags together with their content, strip attributes, remove scripts and add rel="nofollow" to links. Broken HTML is repaired along the way, for example unclosed tags are closed.
It uses the HtmlSanitizer library. Unlike the library's defaults, the action starts permissive: it keeps every tag, attribute, class and CSS property unless you tell it to remove them.
This action requires the Scripting feature (Standard.Scripting) to be licensed. If it isn't licensed, the action fails with an error.
Typical Use Cases
- Clean HTML typed by users before you save it or show it on a page, for example when a field has Secure Input turned off
- Clean HTML received from a Server Request or an incoming email before you store it
- Clean the HTML made by Markdown to Html when the markdown comes from users or an AI model
- Remove tags you don't want in an email or PDF, such as
iframeorstyle - Add
rel="nofollow"to every link in user content
Don't use it to
- Prevent SQL injection. Use bind tokens in Run SQL Query instead.
- Extract the main content of a web page. Use Clean HTML instead.
- Replace text patterns. Use Regex Replace instead.
- Sanitize several values at once. Use one action per value.
Related Actions
| Action Name | Description |
|---|---|
| Markdown to Html | Converts Markdown to HTML. Sanitize its output when the markdown isn't trusted. |
| Display Message | Shows a message. Token values are inserted without encoding, so sanitize user HTML first. |
| Clean HTML | Extracts the main content from a full HTML page. |
| Regex Replace | Replaces text that matches a regular expression. |
| Send Email | Sends an email. Sanitize user HTML before you put it in the body. |
| Generate PDF | Creates a PDF from an HTML template. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Html Content | The HTML to clean, usually a token such as [Comments]. | Yes | empty string | No |
| Convert links to nofollow | Sets rel="nofollow" on every <a> tag. An existing rel value is replaced. | No | False | No |
| Disable scripts | Removes <script> tags with their content. It also removes a built-in list of attributes from every tag: the on... event handlers (such as onclick, onload, onerror) and href, src, action, formaction, xlink:href and srcdoc. See What Disable scripts removes. | No | True | No |
| Toggle between Exclude/Allow HTML tag lists | Unchecked (Exclude mode): only the tags in Excluded Tags are stripped. Checked (Allow mode): every tag is stripped except the ones in Allowed Tags. | No | False (Exclude mode) | No |
| Excluded Tags | Shown in Exclude mode. Tags to strip, for example iframe. The tag is removed but its content stays. All other tags are kept. | Yes | empty list | No |
| Allowed Tags | Shown in Allow mode. The only tags to keep, for example p, b, a. Every other tag is removed but its content stays. With an empty list, all tags are stripped. | Yes | empty list | No |
| Removable Tags | Tags to remove together with everything inside them, for example style. | Yes | empty list | No |
| Removable attributes | Attributes to remove from every tag, for example style or class. All other attributes are kept. | Yes | empty list | No |
| Output Token Name | The token name that gets the cleaned HTML, for example CleanComments. | No | empty string | No |
Tag and attribute names aren't case-sensitive.
Output Parameters Reference
| Parameter | Description |
|---|---|
| Output Token Name | Holds the cleaned HTML. If Output Token Name is empty, nothing is stored. |
How the HTML is processed
- Excluded or not allowed tags are unwrapped. The tag goes, its text and child tags stay and are processed too.
- Removable Tags are deleted with all their content.
- Attributes are all kept, except the ones in Removable attributes and, when Disable scripts is on, the built-in script list.
- Classes and inline CSS are kept. To drop them, add
classorstyleto Removable attributes. - URLs aren't checked. A link like
href="javascript:..."isn't cleaned. It's only removed when Disable scripts is on, because that removes everyhref. - HTML comments are removed.
- Broken HTML is repaired. The HTML is parsed and written back out, so unclosed tags are closed and special characters in text are encoded, for example
&becomes&. - Only the body content is returned. If you pass a full page, the
<html>,<head>and<body>wrappers aren't in the result. - Empty input is returned as-is.
What Disable scripts removes
Disable scripts is on by default. Besides <script> tags, it removes these attributes from every tag:
- Mouse:
onclick,ondblclick,onmousedown,onmouseup,onmouseover,onmouseout,onmousemove,onmouseenter,onmouseleave,oncontextmenu - Keyboard:
onkeydown,onkeypress,onkeyup - Form:
onsubmit,onchange,oninput,oninvalid,onreset,onselect - Focus:
onfocus,onblur,onfocusin,onfocusout - Window:
onload,onbeforeunload,onunload,onresize,onscroll,onerror - Media:
onplay,onpause,onended,ontimeupdate,onvolumechange,onwaiting - Drag and clipboard:
ondrag,ondrop,ondragstart,ondragover,oncopy,oncut,onpaste - Animation and pointer:
onanimationstart,onanimationend,onanimationiteration,ontransitionend,ontoggle,onpointerdown,onpointerup,onwheel - URL attributes:
href,src,action,formaction,xlink:href,srcdoc
This means links lose their target and images lose their source, even safe ones. If you need to keep links and images, turn Disable scripts off and remove scripts yourself: add script to Removable Tags and the event attributes you care about to Removable attributes. Keep in mind that javascript: links then pass through.
Before and after
Input used in all three samples:
<p onclick="steal()">Hi <b>there</b></p><script>alert(1)</script><a href="https://example.com">Site</a>
Default settings (Exclude mode, empty lists, Disable scripts on):
<p>Hi <b>there</b></p><a>Site</a>
Disable scripts off, Removable Tags script, Removable attributes onclick, Convert links to nofollow on:
<p>Hi <b>there</b></p><a href="https://example.com" rel="nofollow">Site</a>
Allow mode, Allowed Tags p, Disable scripts off, Removable Tags script:
<p onclick="steal()">Hi there</p>alert(1)Site
The last sample shows two traps of Allow mode: attributes on allowed tags are kept, and the script's code stays as text. See Considerations.
Considerations
- Scripting license. The action needs the
Standard.Scriptingfeature. If it isn't licensed, the action fails with an error. - Removable Tags run last. Stripped tags are unwrapped first, so their content stays. In Allow mode, a tag in Removable Tags, including the
scripttag added by Disable scripts, must also be in Allowed Tags for its content to be deleted. In Exclude mode, don't put it in Excluded Tags. - One list for both modes. Excluded Tags and Allowed Tags are the same setting. If you switch modes, your list stays but its meaning flips. Check the list after switching.
- Attributes are always a deny list. Even in Allow mode, only the attributes you list (plus the Disable scripts list) are removed.
- The defaults aren't a full XSS filter. Out of the box, the action keeps
iframe,object,form,styletags and inline styles. For untrusted input, use Allow mode with a short list, or add risky tags to Removable Tags. - Compared to Secure Input. The Secure Input option on form fields uses an allow list of tags, attributes and CSS properties, removes classes and keeps
hrefandsrc. This action gives you finer control but starts from "keep everything". - Display Message doesn't encode tokens. Display Message inserts token values as HTML. Sanitize user content before you show it there.
Examples
To understand how to use the below examples, please see Running Examples.
1. Remove scripts and event handlers
This action uses the default settings. Scripts, event attributes, href and src are removed. The result is stored in CleanComments.
{
"Title": "Sanitize Html",
"ActionType": "Parsing.SanitizeHtml",
"Description": "Remove scripts from the comments",
"Parameters": {
"HtmlContent": "[Comments]",
"ForceAnchorNoFollow": false,
"DisableScripts": true,
"IsAllowedMode": false,
"TagsList": [],
"RemovableTags": [],
"RemovableAttributes": [],
"OutputTokenName": "CleanComments"
}
}
2. Allow only basic formatting and keep links
This action keeps a short list of tags and keeps links. Disable scripts is off so href survives. script, style and iframe are deleted with their content, which is why they're also in the allowed list. Event attributes and inline styles are removed, and links get rel="nofollow".
{
"Title": "Sanitize Html",
"ActionType": "Parsing.SanitizeHtml",
"Description": "Keep basic formatting in the bio",
"Condition": "[Bio] != \"\"",
"Parameters": {
"HtmlContent": "[Bio]",
"ForceAnchorNoFollow": true,
"DisableScripts": false,
"IsAllowedMode": true,
"TagsList": [
"p",
"br",
"b",
"strong",
"i",
"em",
"ul",
"ol",
"li",
"a",
"script",
"style",
"iframe"
],
"RemovableTags": [
"script",
"style",
"iframe"
],
"RemovableAttributes": [
"style",
"onclick",
"onmouseover",
"onerror",
"onload"
],
"OutputTokenName": "CleanBio"
}
}
javascript: links aren't removed in this setup. If users can't be trusted with links, keep Disable scripts on.
Revised 09/27/2026