export const defaultSanitizeHtmlOptions = { allowedTags: [ "b", "i", "em", "strong", "a", "p", "span", "ul", "ol", "li", "h1", "h2", "h3", "h4", "h5", "h6", "img", "div", "button", "pre", "code", "br", "hr", "blockquote", "table", "tr", "td", "th", "thead", "tbody", "tfoot", "caption", "colgroup", "col", ], allowedAttributes: { a: ["href", "title", "class", "style", "target", "rel"], img: ["src", "alt", "width", "height", "class", "style"], "*": ["style", "class", "title", "id"], }, }; function uniqueStrings(values) { return Array.from(new Set(values)); } /** * Build sanitize-html options, appending any tags/attributes from config. */ export default function getSanitizeHtmlOptions(config) { const cfg = config || global.CONFIG; const extra = cfg?.html_sanitize; const baseTags = defaultSanitizeHtmlOptions.allowedTags || []; const baseAttrs = { ...(defaultSanitizeHtmlOptions.allowedAttributes || {}), }; const allowedTags = uniqueStrings([ ...(Array.isArray(baseTags) ? baseTags : []), ...(extra?.allowed_tags || []), ]); const allowedAttributes = { ...baseAttrs }; for (const [tag, attrs] of Object.entries(extra?.allowed_attributes || {})) { allowedAttributes[tag] = uniqueStrings([ ...(allowedAttributes[tag] || []), ...attrs, ]); } return { allowedTags, allowedAttributes, }; }