Analyzing your prompt, please hold on...
An error occurred while retrieving the results. Please refresh the page and try again.
To restrict untrusted HTML in Python, create a
Configuration, add the required
Sandbox flags to configuration.security, and pass that configuration to HTMLDocument when loading the source. Apply the restrictions before the document is created.
Aspose.HTML for Python via .NET sandbox flags control selected capabilities of an HTML document during loading and processing. They can block script execution, image loading, form submission, plugins, navigation, and other browser-like behavior.
Use these restrictions when an application processes HTML from users, external systems, email content, scraped pages, or another source that is not fully controlled. Aspose.HTML sandboxing is a document-processing control, not an operating-system security boundary. It should complement normal process, file-system, and network protections rather than replace them.
Set one or more flags through the security property of a Configuration instance. The same configured instance must then be passed to the HTMLDocument constructor.
The reusable workflow is:
Configuration instance.Sandbox flags to configuration.security.Combine restrictions with the bitwise OR operator when several capabilities must be blocked:
1configuration.security |= ah.Sandbox.SCRIPTS | ah.Sandbox.IMAGESApply the flags before creating HTMLDocument; changing the configuration after loading does not retroactively change how the source was processed.
Use Sandbox.SCRIPTS when scripts from the HTML source must not execute. This is useful for static conversion workflows that do not depend on JavaScript-generated content.
The following example loads an HTML file with scripts disabled and converts the resulting document to PDF:
Configuration instance.Sandbox.SCRIPTS to its security settings. 1# Disable JavaScript when converting HTML to PDF in Python
2
3import os
4import aspose.html as ah
5import aspose.html.converters as conv
6import aspose.html.saving as sav
7
8# Prepare input and output paths
9data_dir = "data"
10output_dir = "output"
11os.makedirs(output_dir, exist_ok=True)
12html_path = os.path.join(data_dir, "document-with-scripts.html")
13output_pdf = os.path.join(output_dir, "document-sandbox.pdf")
14
15# Block scripts and convert HTML to PDF
16with ah.Configuration() as config:
17 config.security |= ah.Sandbox.SCRIPTS
18
19 with ah.HTMLDocument(html_path, config) as doc:
20 conv.Converter.convert_html(doc, sav.PdfSaveOptions(), output_pdf)Because script execution is blocked during loading, content that normally appears only after JavaScript runs will not be generated. Static HTML and CSS can still be processed.
Use Sandbox.IMAGES when the document should be processed without loading image resources. The restriction applies to image loading generally, including images referenced by HTML or CSS; it is not limited to remote URLs.
The example creates HTML containing a CSS background image, loads it with image loading disabled, and converts the document to PDF:
Configuration and add Sandbox.IMAGES to its security settings. 1# Block external images when converting HTML to PDF in Python
2
3import os
4import aspose.html as ah
5import aspose.html.converters as conv
6import aspose.html.saving as sav
7
8# Prepare output paths
9output_dir = "output"
10os.makedirs(output_dir, exist_ok=True)
11html_path = os.path.join(output_dir, "sandboxing.html")
12output_pdf = os.path.join(output_dir, "sandboxing-out.pdf")
13
14# Define HTML that references an external image
15code = (
16 "<span style=\"background-image:url('https://docs.aspose.com/html/images/work/lioness.jpg')\">"
17 "Hello, World!!</span> <script>document.write('Have a nice day!');</script>"
18)
19
20# Save the source HTML file
21with open(html_path, "w", encoding="utf-8") as file:
22 file.write(code)
23
24# Block image loading and convert HTML to PDF
25with ah.Configuration() as configuration:
26 configuration.security |= ah.Sandbox.IMAGES
27
28 with ah.HTMLDocument(html_path, configuration) as document:
29 conv.Converter.convert_html(document, sav.PdfSaveOptions(), output_pdf)The resulting document keeps the processable HTML and text content, but image resources are not loaded. The script in this sample is not blocked because only Sandbox.IMAGES is set; combine flags when both images and scripts must be restricted.
The Sandbox enumeration is a flag set, so a configuration can use one restriction or combine several. Choose only the capabilities that the workflow needs to block.
| Flag | Restricted capability |
|---|---|
Sandbox.NONE | No sandbox restriction is applied. |
Sandbox.NAVIGATION | Navigation of other browsing contexts. |
Sandbox.AUXILIARY_NAVIGATION | Creation of auxiliary browsing contexts, such as popups. |
Sandbox.TOP_LEVEL_NAVIGATION | Navigation or closing of the top-level browsing context. |
Sandbox.PLUGINS | Plugin instantiation through plugin-related content. |
Sandbox.ORIGIN | Same-origin access by forcing content into a unique origin. |
Sandbox.FORMS | Form submission. |
Sandbox.POINTER_LOCK | Use of the Pointer Lock API. |
Sandbox.SCRIPTS | Script execution. |
Sandbox.AUTOMATIC_FEATURES | Automatically triggered features, such as autoplay or autofocus. |
Sandbox.FULLSCREEN | Requests to enter fullscreen mode. |
Sandbox.DOCUMENT_DOMAIN | Changes to the effective script origin through document.domain. |
Sandbox.IMAGES | Image loading. |
| Issue | Cause and recommended action |
|---|---|
| Scripts still affect the output | The document was loaded before Sandbox.SCRIPTS was applied, or a different Configuration instance was passed to HTMLDocument. Configure security first and reuse the same instance. |
| JavaScript-generated content is missing | Blocking scripts also blocks content created by those scripts. Allow scripts when the required page content depends on JavaScript and the source is trusted. |
| Images still appear | Verify that Sandbox.IMAGES was applied before loading and that the visible content is actually an image resource rather than CSS color, text, or vector markup. |
| More behavior is blocked than expected | Too many flags were combined. Begin with the narrowest restriction and add another flag only when required. |
| Only particular URLs should be blocked | Sandbox flags restrict broad capability categories. Apply request-level rules in the application’s network layer when URL-specific control is required. |
| Sandboxing is treated as complete isolation | Sandbox flags do not isolate the Python process, operating system, file system, or network environment. Use ordinary application security controls as well. |
Add Sandbox.SCRIPTS to configuration.security before creating the HTMLDocument, then convert or render the document loaded with that configuration.
No. Sandbox.IMAGES disables image loading as a capability. It is not limited to images downloaded from remote URLs.
Yes. Combine flags with the bitwise OR operator, for example ah.Sandbox.SCRIPTS | ah.Sandbox.IMAGES, and add the result to configuration.security.
No. It restricts selected document capabilities inside Aspose.HTML. Continue to use appropriate process isolation, file permissions, network policies, input validation, and other application security measures.
Analyzing your prompt, please hold on...
An error occurred while retrieving the results. Please refresh the page and try again.