<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN"
<title>Simple Web Application Cajoler</title>
<script src="html4-defs.js"></script>
<script src="../../src/com/google/caja/plugin/html-sanitizer.js"></script>
<h1>Original Content</h1>
<div id="original"></div>
<h1>Cajoled Content</h1>
<div id="cajoled"></div>
//build mixed HTML / JavaScript content string
var content = '<h2>Testing Web Cajoler</h2>\n'
+ '<a href="javascript:alert(0)">'
+ '<img src=""></a>\n'
+ '<a href="">test</a>\n'
+ '<script src=""><\/script>';
//display original content before cajoling
document.getElementById("original").innerText = content;
//display cajoled content
document.getElementById("cajoled").innerText = html_sanitize(content);
