PPM AntiSamy

AntiSamy is an HTML, CSS, and JavaScript filter that sanitizes use input based on a policy file. PPM AntiSamy gains wisdom from the OWASP AntiSamy project. For more information about OWASP AntiSamy project, refer to the OWASP documentation.

PPM AntiSamy makes sure user's HTML, CSS and JavaScript input strictly follows rules defined by the policy file antisamy-ppm.xml. For example, if you enable the AntiSamy feature, you cannot open hyperlinks on request details page or project details page. This is because the hyperlink-kind input by default does not meet the rules defined by antisamy-ppm.xml. To make hyperlinks accessible in PPM, you can configure the policy file as you demand.

For more information about using PPM AntiSamy, see Administer Project and Portfolio Management.