API reference
The complete reference for @johnhenry/safe-fragment, checked against src/index.ts. The guide pages are the guided tour; this
is the lookup table. There is a single entry point, @johnhenry/safe-fragment (plus ./package.json), shipped as ESM and CJS.
Importing it never touches window, document, HTMLElement or customElements.
| Page | Covers |
|---|---|
| Element | registerSafeFragment, getSafeFragmentElementClass, createSafeFragmentElementClass, registerExampleSandbox, the element interface, event types, and the fetch capability. |
| Profiles | registerProfile, unregisterProfile, deriveProfile, getProfile, listProfiles, the profile types, built-in names, custom-element name helpers. |
| Errors | SafeFragmentError, isSafeFragmentError, and every error code. |
| URL policy | checkUrl and its constants. |
| Registry | The profile registry and the shared state: how profiles are stored and found. |
For the sanitizer functions see Sanitizing without the element.
Runtime exports
Section titled “Runtime exports”Every value exported from the package root (25 in all).
| Export | Kind | Page |
|---|---|---|
registerSafeFragment(options?) |
function | Element |
getSafeFragmentElementClass(htmlElementBase?) |
function | Element |
createSafeFragmentElementClass(HTMLElementBase, deps) |
function | Element |
registerExampleSandbox(options?) |
function | Element |
DEFAULT_FETCH_CAPABILITY |
constant | Element |
registerProfile(definition) |
function | Profiles |
unregisterProfile(name) |
function | Profiles |
deriveProfile(base, overrides) |
function | Profiles |
getProfile(name) |
function | Profiles |
listProfiles() |
function | Profiles |
RESERVED_CUSTOM_ELEMENT_NAMES |
constant | Profiles |
isValidCustomElementName(name) |
function | Profiles |
PLAIN_TEXT_V1, ARTICLE_V1, UI_V1, EMAIL_V1, COMPONENT_TEMPLATE_V1 |
constants (name strings) | Profiles |
sanitizeToFragment(html, options) |
function | Sanitize API |
sanitizeToFragmentSync(html, options) |
function | Sanitize API |
preloadSanitizer(options?) |
function | Sanitize API |
SafeFragmentError |
class | Errors |
isSafeFragmentError(value) |
function | Errors |
checkUrl(rawValue, allowedSchemes, base?) |
function | URL policy |
SAFE_DEFAULT_URL_SCHEMES |
constant | URL policy |
RELATIVE_URL_SCHEME |
constant | URL policy |
The five constants PLAIN_TEXT_V1, ARTICLE_V1, UI_V1, EMAIL_V1 and COMPONENT_TEMPLATE_V1 are counted individually above.
Type exports
Section titled “Type exports”| Type | Page |
|---|---|
SafeFragmentElement, SafeFragmentEventMap |
Element |
SafeFragmentElementDeps, RegisterSafeFragmentOptions, RegisterExampleSandboxOptions, FetchCapability |
Element |
RenderMode, RenderScope, IdPolicy, SourceKind, RenderResult |
Element |
BeforeRenderDetail, RenderDetail, RejectDetail, ActionDetail, LinkDetail, ClearDetail |
Element |
SanitizerEngineKind, SanitizationNote, SanitizationReport |
Element |
SanitizeToFragmentOptions, SanitizeToFragmentResult, PreloadSanitizerOptions |
Sanitize API |
DOMPurifyFactory, DOMPurifyLoader, DOMPurifyLike |
Sanitize API |
ProfileDefinition, CustomElementAllowlistEntry, DeriveProfileOverrides, BuiltInProfileName |
Profiles |
SafeFragmentErrorCode |
Errors |
UrlCheckResult |
URL policy |