|
| 1 | +const ALLOWED_TAGS = new Set(['p', 'br', 'ul', 'ol', 'li', 'strong', 'em', 'b', 'i', 'code', 'pre']) |
| 2 | +const DROP_CONTENT_TAGS = new Set(['script', 'style', 'iframe', 'object', 'embed']) |
| 3 | + |
| 4 | +const sanitizeNodes = (doc: Document, nodes: ChildNode[]): Node[] => { |
| 5 | + return nodes.flatMap(node => { |
| 6 | + if (node.nodeType === Node.TEXT_NODE) { |
| 7 | + return [doc.createTextNode(node.textContent ?? '')] |
| 8 | + } |
| 9 | + |
| 10 | + if (node.nodeType !== Node.ELEMENT_NODE) { |
| 11 | + return [] |
| 12 | + } |
| 13 | + |
| 14 | + const element = node as HTMLElement |
| 15 | + const tagName = element.tagName.toLowerCase() |
| 16 | + |
| 17 | + if (DROP_CONTENT_TAGS.has(tagName)) { |
| 18 | + return [] |
| 19 | + } |
| 20 | + |
| 21 | + const children = sanitizeNodes(doc, Array.from(element.childNodes)) |
| 22 | + |
| 23 | + if (!ALLOWED_TAGS.has(tagName)) { |
| 24 | + return children |
| 25 | + } |
| 26 | + |
| 27 | + const sanitizedElement = doc.createElement(tagName) |
| 28 | + children.forEach(child => { |
| 29 | + sanitizedElement.appendChild(child) |
| 30 | + }) |
| 31 | + return [sanitizedElement] |
| 32 | + }) |
| 33 | +} |
| 34 | + |
| 35 | +export const sanitizeReleaseNotes = (releaseNotes: string) => { |
| 36 | + const template = document.createElement('template') |
| 37 | + template.innerHTML = releaseNotes |
| 38 | + |
| 39 | + const container = document.createElement('div') |
| 40 | + sanitizeNodes(document, Array.from(template.content.childNodes)).forEach(node => { |
| 41 | + container.appendChild(node) |
| 42 | + }) |
| 43 | + return container.innerHTML |
| 44 | +} |
| 45 | + |
| 46 | +export default sanitizeReleaseNotes |
0 commit comments