Search code examples

HTML Agility Pack strip tags NOT IN whitelist

I'm trying to create a function which removes html tags and attributes which are not in a white list. I have the following HTML:

<b>first text </b>
<b>second text here
       <a>some text here</a>
 <a>some text here</a>

<a>some twxt here</a>

I am using HTML agility pack and the code I have so far is:

static List<string> WhiteNodeList = new List<string> { "b" };
static List<string> WhiteAttrList = new List<string> { };
static HtmlNode htmlNode;
public static void RemoveNotInWhiteList(out string _output, HtmlNode pNode, List<string> pWhiteList, List<string> attrWhiteList)

 // remove all attributes not on white list
 foreach (var item in pNode.ChildNodes)
  item.Attributes.Where(u => attrWhiteList.Contains(u.Name) == false).ToList().ForEach(u => RemoveAttribute(u));


 // remove all html and their innerText and attributes if not on whitelist.
 //pNode.ChildNodes.Where(u => pWhiteList.Contains(u.Name) == false).ToList().ForEach(u => u.Remove());
 //pNode.ChildNodes.Where(u => pWhiteList.Contains(u.Name) == false).ToList().ForEach(u => u.ParentNode.ReplaceChild(ConvertHtmlToNode(u.InnerHtml),u));
 //pNode.ChildNodes.Where(u => pWhiteList.Contains(u.Name) == false).ToList().ForEach(u => u.Remove());

 for (int i = 0; i < pNode.ChildNodes.Count; i++)
  if (!pWhiteList.Contains(pNode.ChildNodes[i].Name))
   HtmlNode _newNode = ConvertHtmlToNode(pNode.ChildNodes[i].InnerHtml);
   pNode.ChildNodes[i].ParentNode.ReplaceChild(_newNode, pNode.ChildNodes[i]);
   if (pNode.ChildNodes[i].HasChildNodes && !string.IsNullOrEmpty(pNode.ChildNodes[i].InnerText.Trim().Replace("\r\n", "")))
    HtmlNode outputNode1 = pNode.ChildNodes[i];
    for (int j = 0; j < pNode.ChildNodes[i].ChildNodes.Count; j++)
     string _childNodeOutput;
     RemoveNotInWhiteList(out _childNodeOutput,
          pNode.ChildNodes[i], WhiteNodeList, WhiteAttrList);
     pNode.ChildNodes[i].ReplaceChild(ConvertHtmlToNode(_childNodeOutput), pNode.ChildNodes[i].ChildNodes[j]);

 // Console.WriteLine(pNode.OuterHtml);
 _output = pNode.OuterHtml;

private static void RemoveAttribute(HtmlAttribute u)
 u.Value = u.Value.ToLower().Replace("javascript", "");


public static HtmlNode ConvertHtmlToNode(string html)
 HtmlAgilityPack.HtmlDocument doc = new HtmlAgilityPack.HtmlDocument();
 if (doc.DocumentNode.ChildNodes.Count == 1)
  return doc.DocumentNode.ChildNodes[0];
 else return doc.DocumentNode;

The output I am tryig to achieve is

<b>first text </b>
<b>second text here
       some text here
 some text here

some twxt here

That means that I only want to keep the <b> tags.
The reason i'm doing this is because Some of the users do cpoy-paste from MS WORD into ny WYSYWYG html editor.



  • heh, apparently I ALMOST found an answer in a blog post someone made....

    using System.Collections.Generic;
    using System.Linq;
    using HtmlAgilityPack;
    namespace Wayloop.Blog.Core.Markup
        public static class HtmlSanitizer
            private static readonly IDictionary<string, string[]> Whitelist;
            static HtmlSanitizer()
                Whitelist = new Dictionary<string, string[]> {
                    { "a", new[] { "href" } },
                    { "strong", null },
                    { "em", null },
                    { "blockquote", null },
            public static string Sanitize(string input)
                var htmlDocument = new HtmlDocument();
                return htmlDocument.DocumentNode.WriteTo().Trim();
            private static void SanitizeChildren(HtmlNode parentNode)
                for (int i = parentNode.ChildNodes.Count - 1; i >= 0; i--) {
            private static void SanitizeNode(HtmlNode node)
                if (node.NodeType == HtmlNodeType.Element) {
                    if (!Whitelist.ContainsKey(node.Name)) {
                    if (node.HasAttributes) {
                        for (int i = node.Attributes.Count - 1; i >= 0; i--) {
                            HtmlAttribute currentAttribute = node.Attributes[i];
                            string[] allowedAttributes = Whitelist[node.Name];
                            if (!allowedAttributes.Contains(currentAttribute.Name)) {
                if (node.HasChildNodes) {

    I got HtmlSanitizer from here Apparently it does not strip th tags, but removes the element altoghether.

    OK, here is the solution for those who will need it later.

    public static class HtmlSanitizer
            private static readonly IDictionary<string, string[]> Whitelist;
            private static List<string> DeletableNodesXpath = new List<string>();
            static HtmlSanitizer()
                Whitelist = new Dictionary<string, string[]> {
                    { "a", new[] { "href" } },
                    { "strong", null },
                    { "em", null },
                    { "blockquote", null },
                    { "b", null},
                    { "p", null},
                    { "ul", null},
                    { "ol", null},
                    { "li", null},
                    { "div", new[] { "align" } },
                    { "strike", null},
                    { "u", null},                
                    { "sub", null},
                    { "sup", null},
                    { "table", null },
                    { "tr", null },
                    { "td", null },
                    { "th", null }
            public static string Sanitize(string input)
                if (input.Trim().Length < 1)
                    return string.Empty;
                var htmlDocument = new HtmlDocument();
                string xPath = HtmlSanitizer.CreateXPath();
                return StripHtml(htmlDocument.DocumentNode.WriteTo().Trim(), xPath);
            private static void SanitizeChildren(HtmlNode parentNode)
                for (int i = parentNode.ChildNodes.Count - 1; i >= 0; i--)
            private static void SanitizeNode(HtmlNode node)
                if (node.NodeType == HtmlNodeType.Element)
                    if (!Whitelist.ContainsKey(node.Name))
                        if (!DeletableNodesXpath.Contains(node.Name))
                            node.Name = "removeableNode";
                        if (node.HasChildNodes)
                    if (node.HasAttributes)
                        for (int i = node.Attributes.Count - 1; i >= 0; i--)
                            HtmlAttribute currentAttribute = node.Attributes[i];
                            string[] allowedAttributes = Whitelist[node.Name];
                            if (allowedAttributes != null)
                                if (!allowedAttributes.Contains(currentAttribute.Name))
                if (node.HasChildNodes)
            private static string StripHtml(string html, string xPath)
                HtmlDocument htmlDoc = new HtmlDocument();
                if (xPath.Length > 0)
                    HtmlNodeCollection invalidNodes = htmlDoc.DocumentNode.SelectNodes(@xPath);
                    foreach (HtmlNode node in invalidNodes)
                        node.ParentNode.RemoveChild(node, true);
                return htmlDoc.DocumentNode.WriteContentTo(); ;
            private static string CreateXPath()
                string _xPath = string.Empty;
                for (int i = 0; i < DeletableNodesXpath.Count; i++)
                    if (i != DeletableNodesXpath.Count - 1)
                        _xPath += string.Format("//{0}|", DeletableNodesXpath[i].ToString());
                    else _xPath += string.Format("//{0}", DeletableNodesXpath[i].ToString());
                return _xPath;

    I renamed the node because if I had to parse an XML namespace node it would crash on the xpath parsing.