ESAPI.printProperties=true ESAPI.Encoder=org.owasp.esapi.reference.DefaultEncoder # ESAPI Encoder Encoder.AllowMultipleEncoding=false Encoder.AllowMixedEncoding=false Encoder.DefaultCodecList=HTMLEntityCodec,PercentCodec,JavaScriptCodec