Team Ai
Datasetpublic

Brunobkr/llama.cpp_AlgMor24_github

ΩFFFΣLLIa • llama.cpp • AlgMor24 ██████╗ ███████╗███████╗███████╗██╗ ██╗ ██╗ █████╗ ██╔═══██╗██╔════╝██╔════╝██╔════╝██║ ██║ ██║██╔══██╗ ██║ ██║█████╗ █████╗ █████╗ ██║ ██║ ██║███████║ ██║ ██║██╔══╝ ██╔══╝ ██╔══╝ ██║ ██║ ██║██╔══██║ ╚██████╔╝██║ ██║ ███████╗███████╗███████╗██║██║ ██║ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝╚══════╝╚══════╝╚═╝╚═╝ ╚═╝ High-Performance LLM / VLM Inference & Autonomous Agentic Ecosystem… See the full description on the dataset page: https://huggingface.co/datasets/Brunobkr/llama.cpp_AlgMor24_github.

sourceHugging Faceupdated 2mo agoView on Hugging Face
0likes3.1kdownloads
README.md569 linesDownload Raw Back to dompurify
1# DOMPurify2 3[![npm](https://img.shields.io/npm/v/dompurify.svg)](https://www.npmjs.com/package/dompurify) [![License](https://img.shields.io/badge/license-MPL--2.0%20OR%20Apache--2.0-blue.svg)](https://github.com/cure53/DOMPurify/blob/main/LICENSE) [![Downloads](https://img.shields.io/npm/dm/dompurify.svg)](https://www.npmjs.com/package/dompurify) [![dependents](https://badgen.net/github/dependents-repo/cure53/dompurify?color=green&label=dependents)](https://github.com/cure53/DOMPurify/network/dependents) ![npm package minimized gzipped size (select exports)](https://img.shields.io/bundlejs/size/dompurify?color=%233C1&label=gzip) [![Cloudback](https://app.cloudback.it/badge/cure53/DOMPurify)](https://cloudback.it)4 5[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/12162/badge)](https://www.bestpractices.dev/projects/12162) [![Build & Test](https://github.com/cure53/DOMPurify/actions/workflows/build-and-test.yml/badge.svg?branch=main)](https://github.com/cure53/DOMPurify/actions/workflows/build-and-test.yml) [![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/cure53/DOMPurify/badge)](https://scorecard.dev/viewer/?uri=github.com/cure53/DOMPurify) [![Socket Badge](https://badge.socket.dev/npm/package/dompurify/latest)](https://badge.socket.dev/npm/package/dompurify/latest) [![snyk.io package health](https://img.shields.io/badge/snyk.io%20package%20health-97%2F100-brightgreen)](https://security.snyk.io/package/npm/dompurify)6 7DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG.8 9It's also very simple to use and get started with. DOMPurify was [started in February 2014](https://github.com/cure53/DOMPurify/commit/a630922616927373485e0e787ab19e73e3691b2b) and, meanwhile, has reached version **v3.4.13**.10 11DOMPurify runs as JavaScript and works in all modern browsers (Safari (10+), Opera (15+), Edge, Firefox and Chrome - as well as almost anything else using Blink, Gecko or WebKit). It doesn't break on MSIE or other legacy browsers. It simply does nothing.12 13**Note that [DOMPurify v2.5.9](https://github.com/cure53/DOMPurify/releases/tag/2.5.9) is the latest version supporting MSIE. For important security updates compatible with MSIE, please use the [2.x branch](https://github.com/cure53/DOMPurify/tree/2.x).**14 15Our automated tests cover 9 browser/OS combinations on the current engines (Chromium, Firefox, and WebKit across Ubuntu, macOS, and Windows) on every push, and a separate matrix re-runs the suite on older engine snapshots (back to roughly Chromium 110, Firefox 108 and WebKit 16.4, around three years old) so regressions on outdated browsers get caught too. We also run Node.js v20, v22, v24, v25 and v26 with DOMPurify on [jsdom](https://github.com/jsdom/jsdom). Older Node versions are known to work as well, but hey... no guarantees.16 17DOMPurify is written by security people who have vast background in web attacks and XSS. Fear not. For more details please also read about our [Security Goals & Threat Model](https://github.com/cure53/DOMPurify/wiki/Security-Goals-&-Threat-Model). Please, read it. Like, really. And if you enjoy the gory details, the [Attack Classes & Bypass History](https://github.com/cure53/DOMPurify/wiki/Attack-Classes-&-Bypass-History) page catalogs the parser-mutation, namespace, clobbering, and template tricks DOMPurify defends against.18 19The DOMPurify project inspired the creation of the [HTML Sanitizer API](https://wicg.github.io/sanitizer-api/#sanitizer), which is already shipping in [many browsers](https://developer.mozilla.org/en-US/docs/Web/API/HTML_Sanitizer_API#browser_compatibility). The same capability is now being standardized directly in the [WHATWG HTML specification](https://html.spec.whatwg.org/#html-sanitization).20 21## Table of Contents22 23- [What does it do?](#what-does-it-do)24- [How do I use it?](#how-do-i-use-it)25- [Is there a demo?](#is-there-a-demo)26- [What if I find a _security_ bug?](#what-if-i-find-a-security-bug)27- [Some purification samples please?](#some-purification-samples-please)28- [What is supported?](#what-is-supported)29- [What about legacy browsers like Internet Explorer?](#what-about-legacy-browsers-like-internet-explorer)30- [What about DOMPurify and Trusted Types?](#what-about-dompurify-and-trusted-types)31- [Can I configure DOMPurify?](#can-i-configure-dompurify)32- [Persistent Configuration](#persistent-configuration)33- [Hooks](#hooks)34- [Removed Configuration](#removed-configuration)35- [Continuous Integration](#continuous-integration)36- [Security Mailing List](#security-mailing-list)37- [Who contributed?](#who-contributed)38 39## What does it do?40 41DOMPurify sanitizes HTML and prevents XSS attacks. You can feed DOMPurify with e.g. a string full of dirty HTML and it will return a string (unless configured otherwise) with clean HTML. DOMPurify will strip out everything that contains dangerous HTML and thereby prevent XSS attacks and other nastiness. It's also damn bloody fast. We use the technologies the browser provides and turn them into an XSS filter. The faster your browser, the faster DOMPurify will be.42 43## How do I use it?44 45It's easy. Just include DOMPurify on your website.46 47### Using the unminified version (source-map available)48 49```html50<script type="text/javascript" src="dist/purify.js"></script>51```52 53### Using the minified and tested production version (source-map available)54 55```html56<script type="text/javascript" src="dist/purify.min.js"></script>57```58 59Afterwards you can sanitize strings by executing the following code:60 61```js62const clean = DOMPurify.sanitize(dirty);63```64 65Or maybe this, if you love working with Angular or alike:66 67```js68import DOMPurify from 'dompurify';69 70const clean = DOMPurify.sanitize('<b>hello there</b>');71```72 73The resulting HTML can be written into a DOM element using `innerHTML` or the DOM using `document.write()`. That is fully up to you.74Note that by default, we permit HTML, SVG **and** MathML. If you only need HTML, which might be a very common use-case, you can easily set that up as well:75 76```js77const clean = DOMPurify.sanitize(dirty, { USE_PROFILES: { html: true } });78```79 80### Is there any foot-gun potential?81 82Well, please note, if you _first_ sanitize HTML and then modify it _afterwards_, you might easily **void the effects of sanitization**. If you feed the sanitized markup to another library _after_ sanitization, please be certain that the library doesn't mess around with the HTML on its own. See the [Security Goals & Threat Model](https://github.com/cure53/DOMPurify/wiki/Security-Goals-&-Threat-Model) for safe-usage recipes and the tags/attributes worth thinking twice about, and [Attack Classes & Bypass History](https://github.com/cure53/DOMPurify/wiki/Attack-Classes-&-Bypass-History) for why post-processing and changing the markup context defeat sanitization.83 84### Okay, makes sense, let's move on85 86After sanitizing your markup, you can also have a look at the property `DOMPurify.removed` and find out, what elements and attributes were thrown out. Please **do not use** this property for making any security critical decisions. This is just a little helper for curious minds.87 88### Running DOMPurify on the server89 90DOMPurify technically also works server-side with Node.js. Our support strives to follow the [Node.js release cycle](https://nodejs.org/en/about/previous-releases).91 92Running DOMPurify on the server requires a DOM to be present, which is probably no surprise. Usually, [jsdom](https://github.com/jsdom/jsdom) is the tool of choice and we **strongly recommend** to use the latest version of _jsdom_.93 94Why? Because older versions of _jsdom_ are known to be buggy in ways that result in XSS _even if_ DOMPurify does everything 100% correctly. There are **known attack vectors** in, e.g. _jsdom v19.0.0_ that are fixed in _jsdom v20.0.0_ - and we really recommend to keep _jsdom_ up to date because of that.95 96Please also be aware that tools like [happy-dom](https://github.com/capricorn86/happy-dom) exist but **are not considered safe** at this point. Combining DOMPurify with _happy-dom_ is currently not recommended and will likely lead to XSS. For background on why the server-side DOM you choose is part of your trusted computing base, see [Attack Classes & Bypass History](https://github.com/cure53/DOMPurify/wiki/Attack-Classes-&-Bypass-History).97 98Other than that, you are fine to use DOMPurify on the server. Probably. This really depends on _jsdom_ or whatever DOM you utilize server-side. If you can live with that, this is how you get it to work:99 100```bash101npm install dompurify102npm install jsdom103```104 105For _jsdom_ (please use an up-to-date version), this should do the trick:106 107```js108const createDOMPurify = require('dompurify');109const { JSDOM } = require('jsdom');110 111const window = new JSDOM('').window;112const DOMPurify = createDOMPurify(window);113const clean = DOMPurify.sanitize('<b>hello there</b>');114```115 116Or even this, if you prefer working with imports:117 118```js119import { JSDOM } from 'jsdom';120import DOMPurify from 'dompurify';121 122const window = new JSDOM('').window;123const purify = DOMPurify(window);124const clean = purify.sanitize('<b>hello there</b>');125```126 127If you have problems making it work in your specific setup, consider looking at the amazing [isomorphic-dompurify](https://github.com/kkomelin/isomorphic-dompurify) project which solves lots of problems people might run into.128 129```bash130npm install isomorphic-dompurify131```132 133```js134import DOMPurify from 'isomorphic-dompurify';135 136const clean = DOMPurify.sanitize('<s>hello</s>');137```138 139## Is there a demo?140 141Of course there is a demo! [Play with DOMPurify](https://cure53.de/purify)142 143## What if I find a security bug?144 145First of all, please immediately contact us via [email](mailto:mario@cure53.de) so we can work on a fix. [PGP key](https://keyserver.ubuntu.com/pks/lookup?op=vindex&search=0xC26C858090F70ADA)146 147Also, you probably qualify for a bug bounty! The fine folks over at [Fastmail](https://www.fastmail.com/) use DOMPurify for their services and added our library to their bug bounty scope. So, if you find a way to bypass or weaken DOMPurify, please also have a look at their website and the [bug bounty info](https://www.fastmail.com/about/bugbounty/).148 149## Some purification samples please?150 151How does purified markup look like? Well, [the demo](https://cure53.de/purify) shows it for a big bunch of nasty elements. But let's also show some smaller examples!152 153```js154DOMPurify.sanitize('<img src=x onerror=alert(1)//>'); // becomes <img src="x">155DOMPurify.sanitize('<svg><g/onload=alert(2)//<p>'); // becomes <svg><g></g></svg>156DOMPurify.sanitize('<p>abc<iframe//src=jAva&Tab;script:alert(3)>def</p>'); // becomes <p>abc</p>157DOMPurify.sanitize('<math><mi//xlink:href="data:x,<script>alert(4)</script>">'); // becomes <math><mi></mi></math>158DOMPurify.sanitize('<TABLE><tr><td>HELLO</tr></TABL>'); // becomes <table><tbody><tr><td>HELLO</td></tr></tbody></table>159DOMPurify.sanitize('<UL><li><A HREF=//google.com>click</UL>'); // becomes <ul><li><a href="//google.com">click</a></li></ul>160```161 162These are just a taste. For the full taxonomy of attack classes these samples come from - mutation XSS, namespace confusion, DOM clobbering, rawtext breakouts, and more - see [Attack Classes & Bypass History](https://github.com/cure53/DOMPurify/wiki/Attack-Classes-&-Bypass-History).163 164## What is supported?165 166DOMPurify currently supports HTML5, SVG and MathML. DOMPurify per default allows CSS, HTML custom data attributes. DOMPurify also supports the Shadow DOM - and sanitizes DOM templates recursively. DOMPurify also allows you to sanitize HTML for being used with the jQuery `$()` and `elm.html()` API without any known problems. For the exact set of elements and attributes permitted by default, see the [Default TAGs & ATTRIBUTEs allow-list & blocklist](https://github.com/cure53/DOMPurify/wiki/Default-TAGs-ATTRIBUTEs-allow-list-&-blocklist) wiki page.167 168## What about legacy browsers like Internet Explorer?169 170DOMPurify does nothing at all. It simply returns exactly the string that you fed it. DOMPurify exposes a property called `isSupported`, which tells you whether it will be able to do its job, so you can come up with your own backup plan.171 172## What about DOMPurify and Trusted Types?173 174In version 1.0.9, support for the [Trusted Types API](https://github.com/w3c/webappsec-trusted-types) ([MDN](https://developer.mozilla.org/en-US/docs/Web/API/Trusted_Types_API)) was added to DOMPurify.175In version 2.0.0, a config flag was added to control DOMPurify's behavior regarding this.176 177When `DOMPurify.sanitize` is used in an environment where the Trusted Types API is available and `RETURN_TRUSTED_TYPE` is set to `true`, it tries to return a `TrustedHTML` value instead of a string (the behavior for `RETURN_DOM` and `RETURN_DOM_FRAGMENT` config options does not change).178 179Note that in order to create a policy in `trustedTypes` using DOMPurify, `RETURN_TRUSTED_TYPE: false` is required, as `createHTML` expects a normal string, not `TrustedHTML`. The example below shows this.180 181```js182window.trustedTypes.createPolicy('default', {183  createHTML: (to_escape) =>184    DOMPurify.sanitize(to_escape, { RETURN_TRUSTED_TYPE: false }),185});186```187 188When no `TRUSTED_TYPES_POLICY` is supplied, DOMPurify attempts to create its own internal Trusted Types policy named `dompurify`. If your page already defines its own policy together with a strict CSP (for example `trusted-types my-organization`) that does not allow a policy named `dompurify`, this attempt is blocked by the browser and logs a `TrustedTypes policy dompurify could not be created.` warning along with a CSP violation.189 190To stop DOMPurify from creating its internal fallback policy, pass `TRUSTED_TYPES_POLICY: null`. This is the right choice when you call `DOMPurify.sanitize` from inside your own policy's `createHTML`, and it means you do not have to add `dompurify` to your CSP's `trusted-types` allowlist.191 192```js193window.trustedTypes.createPolicy('my-organization', {194  createHTML: (input) =>195    DOMPurify.sanitize(input, { TRUSTED_TYPES_POLICY: null }),196});197```198 199Do **not** pass your own wrapping policy back to DOMPurify as its `TRUSTED_TYPES_POLICY` (for example via `DOMPurify.setConfig({ TRUSTED_TYPES_POLICY: myPolicy })`) when that policy's `createHTML` already calls `DOMPurify.sanitize`. That is circular by definition - sanitizing would call the policy, which sanitizes by calling DOMPurify again - and DOMPurify will throw a descriptive `TypeError` to prevent the infinite recursion. Your own policy should call DOMPurify; DOMPurify should not be configured to call your policy.200 201If you want this `default`-policy pattern applied across an entire page automatically - so that every HTML sink is sanitized, including legacy code, third-party widgets, and the thousands of `innerHTML` assignments you cannot easily find or rewrite - have a look at [DOMFortify](https://github.com/cure53/DOMFortify). It installs exactly such a Trusted Types `default` policy backed by DOMPurify and refuses script sinks (`eval`, `script.src`, ...) outright. It is a deliberately separate project: DOMPurify stays a focused sanitizer, and DOMFortify handles the document-wide enforcement layer that is intentionally out of DOMPurify's scope.202 203## Can I configure DOMPurify?204 205Yes. The included default configuration values are pretty good already - but you can of course override them. Check out the [`/demos`](https://github.com/cure53/DOMPurify/tree/main/demos) folder to see a bunch of examples on how you can [customize DOMPurify](https://github.com/cure53/DOMPurify/tree/main/demos#what-is-this).206 207Before you widen the allow-list (`ADD_TAGS`, `ADD_ATTR`, `CUSTOM_ELEMENT_HANDLING`, …) or relax a default, it's worth skimming the [tags and attributes to think twice about](https://github.com/cure53/DOMPurify/wiki/Security-Goals-&-Threat-Model#dangerous-tags-and-attributes-think-twice-before-allow-listing) - a few are dangerous in non-obvious ways.208 209### General settings210 211```js212// strip {{ ... }}, ${ ... } and <% ... %> to make output safe for template systems213// be careful please, this mode is not recommended for production usage.214// allowing template parsing in user-controlled HTML is not advised at all.215// only use this mode if there is really no alternative.216const clean = DOMPurify.sanitize(dirty, { SAFE_FOR_TEMPLATES: true });217 218// change how e.g. comments containing risky HTML characters are treated.219// be very careful, this setting should only be set to `false` if you really only handle220// HTML and nothing else, no SVG, MathML or the like.221// Otherwise, changing from `true` to `false` will lead to XSS in this or some other way.222const clean = DOMPurify.sanitize(dirty, { SAFE_FOR_XML: false });223```224 225### Control our allow-lists and block-lists226 227```js228// allow only <b> elements, very strict229const clean = DOMPurify.sanitize(dirty, { ALLOWED_TAGS: ['b'] });230 231// allow only <b> and <q> with style attributes232const clean = DOMPurify.sanitize(dirty, {233  ALLOWED_TAGS: ['b', 'q'],234  ALLOWED_ATTR: ['style'],235});236 237// allow all safe HTML elements but neither SVG nor MathML238// note that the USE_PROFILES setting will override the ALLOWED_TAGS setting239// so don't use them together240const clean = DOMPurify.sanitize(dirty, { USE_PROFILES: { html: true } });241 242// allow all safe SVG elements and SVG Filters, no HTML or MathML243const clean = DOMPurify.sanitize(dirty, {244  USE_PROFILES: { svg: true, svgFilters: true },245});246 247// allow all safe MathML elements and SVG, but no SVG Filters248const clean = DOMPurify.sanitize(dirty, {249  USE_PROFILES: { mathMl: true, svg: true },250});251 252// change the default namespace from HTML to something different253const clean = DOMPurify.sanitize(dirty, {254  NAMESPACE: 'http://www.w3.org/2000/svg',255});256 257// leave all safe HTML as it is and add <style> elements to block-list258const clean = DOMPurify.sanitize(dirty, { FORBID_TAGS: ['style'] });259 260// leave all safe HTML as it is and add style attributes to block-list261const clean = DOMPurify.sanitize(dirty, { FORBID_ATTR: ['style'] });262 263// extend the existing array of allowed tags and add <my-tag> to allow-list264const clean = DOMPurify.sanitize(dirty, { ADD_TAGS: ['my-tag'] });265 266// extend the existing array of allowed attributes and add my-attr to allow-list267const clean = DOMPurify.sanitize(dirty, { ADD_ATTR: ['my-attr'] });268 269// use functions to control which additional tags and attributes are allowed270const allowlist = {271  one: ['attribute-one'],272  two: ['attribute-two'],273};274const clean = DOMPurify.sanitize(275  '<one attribute-one="1" attribute-two="2"></one><two attribute-one="1" attribute-two="2"></two>',276  {277    ADD_TAGS: (tagName) => {278      return Object.keys(allowlist).includes(tagName);279    },280    ADD_ATTR: (attributeName, tagName) => {281      return allowlist[tagName]?.includes(attributeName) || false;282    },283  }284); // <one attribute-one="1"></one><two attribute-two="2"></two>285 286// prohibit ARIA attributes, leave other safe HTML as is (default is true)287const clean = DOMPurify.sanitize(dirty, { ALLOW_ARIA_ATTR: false });288 289// prohibit HTML5 data attributes, leave other safe HTML as is (default is true)290const clean = DOMPurify.sanitize(dirty, { ALLOW_DATA_ATTR: false });291```292 293### Control behavior relating to Custom Elements294 295```js296// DOMPurify allows to define rules for Custom Elements. When using the CUSTOM_ELEMENT_HANDLING297// literal, it is possible to define exactly what elements you wish to allow (by default, none are allowed).298//299// The same goes for their attributes. By default, the built-in or configured allow.list is used.300//301// You can use a RegExp literal to specify what is allowed or a predicate, examples for both can be seen below.302// When using a predicate function for attributeNameCheck, it can optionally receive the tagName as a second parameter303// for more granular control over which attributes are allowed for specific elements.304// The default values are very restrictive to prevent accidental XSS bypasses. Handle with great care!305 306const clean = DOMPurify.sanitize(307  '<foo-bar baz="foobar" forbidden="true"></foo-bar><div is="foo-baz"></div>',308  {309    CUSTOM_ELEMENT_HANDLING: {310      tagNameCheck: null, // no custom elements are allowed311      attributeNameCheck: null, // default / standard attribute allow-list is used312      allowCustomizedBuiltInElements: false, // no customized built-ins allowed313    },314  }315); // <div is=""></div>316 317const clean = DOMPurify.sanitize(318  '<foo-bar baz="foobar" forbidden="true"></foo-bar><div is="foo-baz"></div>',319  {320    CUSTOM_ELEMENT_HANDLING: {321      tagNameCheck: /^foo-/, // allow all tags starting with "foo-"322      attributeNameCheck: /baz/, // allow all attributes containing "baz"323      allowCustomizedBuiltInElements: true, // customized built-ins are allowed324    },325  }326); // <foo-bar baz="foobar"></foo-bar><div is="foo-baz"></div>327 328const clean = DOMPurify.sanitize(329  '<foo-bar baz="foobar" forbidden="true"></foo-bar><div is="foo-baz"></div>',330  {331    CUSTOM_ELEMENT_HANDLING: {332      tagNameCheck: (tagName) => tagName.match(/^foo-/), // allow all tags starting with "foo-"333      attributeNameCheck: (attr) => attr.match(/baz/), // allow all containing "baz"334      allowCustomizedBuiltInElements: true, // allow customized built-ins335    },336  }337); // <foo-bar baz="foobar"></foo-bar><div is="foo-baz"></div>338 339// Example with attributeNameCheck receiving tagName as a second parameter340const clean = DOMPurify.sanitize(341  '<element-one attribute-one="1" attribute-two="2"></element-one><element-two attribute-one="1" attribute-two="2"></element-two>',342  {343    CUSTOM_ELEMENT_HANDLING: {344      tagNameCheck: (tagName) => tagName.match(/^element-(one|two)$/),345      attributeNameCheck: (attr, tagName) => {346        if (tagName === 'element-one') {347          return ['attribute-one'].includes(attr);348        } else if (tagName === 'element-two') {349          return ['attribute-two'].includes(attr);350        } else {351          return false;352        }353      },354      allowCustomizedBuiltInElements: false,355    },356  }357); // <element-one attribute-one="1"></element-one><element-two attribute-two="2"></element-two>358```359 360### Control behavior relating to URI values361 362```js363// extend the existing array of elements that can use Data URIs364const clean = DOMPurify.sanitize(dirty, { ADD_DATA_URI_TAGS: ['a', 'area'] });365 366// extend the existing array of elements that are safe for URI-like values (be careful, XSS risk)367const clean = DOMPurify.sanitize(dirty, { ADD_URI_SAFE_ATTR: ['my-attr'] });368```369 370### Control permitted attribute values371 372```js373// allow external protocol handlers in URL attributes (default is false, be careful, XSS risk)374// by default only http, https, ftp, ftps, tel, mailto, callto, sms, cid, xmpp and matrix are allowed.375const clean = DOMPurify.sanitize(dirty, { ALLOW_UNKNOWN_PROTOCOLS: true });376 377// allow specific protocol handlers in URL attributes via regex (default is false, be careful, XSS risk)378// by default only (protocol-)relative URLs, http, https, ftp, ftps, tel, mailto, callto, sms, cid, xmpp and matrix are allowed.379// Default RegExp: /^(?:(?:(?:f|ht)tps?|mailto|tel|callto|sms|cid|xmpp):|[^a-z]|[a-z+.\-]+(?:[^a-z+.\-:]|$))/i;380const clean = DOMPurify.sanitize(dirty, {381  ALLOWED_URI_REGEXP:382    /^(?:(?:(?:f|ht)tps?|mailto|tel|callto|sms|cid|xmpp|matrix):|[^a-z]|[a-z+.\-]+(?:[^a-z+.\-:]|$))/i,383});384```385 386### Influence the return-type387 388```js389// return a DOM HTMLBodyElement instead of an HTML string (default is false)390const clean = DOMPurify.sanitize(dirty, { RETURN_DOM: true });391 392// return a DOM DocumentFragment instead of an HTML string (default is false)393const clean = DOMPurify.sanitize(dirty, { RETURN_DOM_FRAGMENT: true });394 395// use the RETURN_TRUSTED_TYPE flag to turn on Trusted Types support if available396const clean = DOMPurify.sanitize(dirty, { RETURN_TRUSTED_TYPE: true }); // will return a TrustedHTML object instead of a string if possible397 398// use a provided Trusted Types policy399const clean = DOMPurify.sanitize(dirty, {400  // supplied policy must define createHTML and createScriptURL401  TRUSTED_TYPES_POLICY: trustedTypes.createPolicy('dompurify', {402    createHTML(s) {403      return s;404    },405    createScriptURL(s) {406      return s;407    },408  }),409});410 411// opt out of DOMPurify's internal `dompurify` Trusted Types policy entirely412// (useful when your CSP `trusted-types` allowlist does not include `dompurify`)413const clean = DOMPurify.sanitize(dirty, { TRUSTED_TYPES_POLICY: null });414```415 416### Influence how we sanitize417 418```js419// return entire document including <html> tags (default is false)420const clean = DOMPurify.sanitize(dirty, { WHOLE_DOCUMENT: true });421 422// disable DOM Clobbering protection on output (default is true, handle with care, minor XSS risks here)423const clean = DOMPurify.sanitize(dirty, { SANITIZE_DOM: false });424 425// enforce strict DOM Clobbering protection via namespace isolation (default is false)426// when enabled, isolates the namespace of named properties (i.e., `id` and `name` attributes)427// from JS variables by prefixing them with the string `user-content-`428const clean = DOMPurify.sanitize(dirty, { SANITIZE_NAMED_PROPS: true });429 430// keep an element's content when the element is removed (default is true)431const clean = DOMPurify.sanitize(dirty, { KEEP_CONTENT: false });432 433// glue elements like style, script or others to document.body and prevent unintuitive browser behavior in several edge-cases (default is false)434const clean = DOMPurify.sanitize(dirty, { FORCE_BODY: true });435 436// remove all <a> elements under <p> elements that are removed437const clean = DOMPurify.sanitize(dirty, {438  FORBID_CONTENTS: ['a'],439  FORBID_TAGS: ['p'],440});441 442// extend the default FORBID_CONTENTS list to also remove <a> elements under <p> elements443const clean = DOMPurify.sanitize(dirty, {444  ADD_FORBID_CONTENTS: ['a'],445  FORBID_TAGS: ['p'],446});447 448// change the parser type so sanitized data is treated as XML and not as HTML, which is the default449const clean = DOMPurify.sanitize(dirty, {450  PARSER_MEDIA_TYPE: 'application/xhtml+xml',451});452```453 454### Influence where we sanitize455 456```js457// use the IN_PLACE mode to sanitize a node "in place", which is much faster depending on how you use DOMPurify458const dirty = document.createElement('a');459dirty.setAttribute('href', 'javascript:alert(1)');460 461const clean = DOMPurify.sanitize(dirty, { IN_PLACE: true }); // see https://github.com/cure53/DOMPurify/issues/288 for more info462```463 464There is even [more examples here](https://github.com/cure53/DOMPurify/tree/main/demos#what-is-this), showing how you can run, customize and configure DOMPurify to fit your needs.465 466## Persistent Configuration467 468Instead of repeatedly passing the same configuration to `DOMPurify.sanitize`, you can use the `DOMPurify.setConfig` method. Your configuration will persist until your next call to `DOMPurify.setConfig`, or until you invoke `DOMPurify.clearConfig` to reset it. Remember that there is only one active configuration, which means once it is set, all extra configuration parameters passed to `DOMPurify.sanitize` are ignored.469 470## Hooks471 472DOMPurify allows you to augment its functionality by attaching one or more functions with the `DOMPurify.addHook` method to one of the following hooks:473 474- `beforeSanitizeElements`475- `uponSanitizeElement` (No 's' - called for every element)476- `afterSanitizeElements`477- `beforeSanitizeAttributes`478- `uponSanitizeAttribute`479- `afterSanitizeAttributes`480- `beforeSanitizeShadowDOM`481- `uponSanitizeShadowNode`482- `afterSanitizeShadowDOM`483 484It passes the currently processed DOM node, when needed a literal with verified node and attribute data and the DOMPurify configuration to the callback. Check out the [MentalJS hook demo](https://github.com/cure53/DOMPurify/blob/main/demos/hooks-mentaljs-demo.html) to see how the API can be used nicely.485 486_Example_:487 488```js489DOMPurify.addHook(490  'uponSanitizeAttribute',491  function (currentNode, hookEvent, config) {492    // Do something with the current node493    // You can also mutate hookEvent for current node (i.e. set hookEvent.forceKeepAttr = true)494    // For other than 'uponSanitizeAttribute' hook types hookEvent equals to null495  }496);497```498 499## Removed Configuration500 501| Option          | Since | Note                     |502| --------------- | ----- | ------------------------ |503| SAFE_FOR_JQUERY | 2.1.0 | No replacement required. |504 505## Continuous Integration506 507We are currently using GitHub Actions in combination with Playwright. This lets us confirm on every commit that everything works in the relevant modern browsers, and a separate scheduled and on-merge workflow re-runs the suite on older engine snapshots so breakage on outdated browsers is caught too. Check out the build logs here: https://github.com/cure53/DOMPurify/actions508 509You can further run local tests by executing `npm run test`.510 511All relevant commits will be signed with the key `0x24BB6BF4` for additional security (since 8th of April 2016).512 513### Development and contributing514 515#### Installation (`npm i`)516 517We support `npm` officially. GitHub Actions workflow is configured to install dependencies using `npm`. When using a deprecated version of `npm`, we cannot fully ensure the versions of installed dependencies, which might lead to unanticipated problems.518 519#### Scripts520 521We use ESLint via `xo` as part of our pre-commit workflow to help ensure code consistency. In addition, we use [Prettier](https://github.com/prettier/prettier) for source and Markdown formatting, and `/dist` assets are built through `rollup`.522 523These are our npm scripts:524 525- `npm run dev` to build the unminified UMD bundle while watching sources for changes526- `npm run test` to lint the sources, run tests through jsdom, and run browser tests in Chromium via Playwright527  - `npm run test:jsdom` to only run tests through jsdom528  - `npm run test:happydom` to run the suite through happy-dom (an unsupported environment; kept as a robustness check, not a compatibility promise)529  - `npm run test:browser` to only run tests through Playwright530  - `npm run test:browser:legacy` to run the suite on older browser engines (point `PW_MODULE` at a pinned old Playwright install; see `.github/workflows/legacy-browsers.yml`)531  - `npm run test:ci` to run the CI test flow for jsdom and Playwright532  - `npm run test:fuzz` to run a small fuzzer covering `sanitize()` and CONFIG533- `npm run bench` to run the jsdom micro-benchmark over the built `dist/purify.cjs` (build first; `--json` and `--compare a.json b.json` support A/B runs across branches - results are directional, confirm user-facing claims in real browsers)534- `npm run coverage` to build an instrumented bundle, run the jsdom suite, and write a local HTML line/branch coverage report to `coverage/index.html` (jsdom scope only, not run in CI)535  - `npm run build:cov` to only build the instrumented coverage bundle536- `npm run lint` to lint the sources using ESLint via xo537- `npm run format` to format JavaScript/TypeScript and Markdown sources with Prettier538  - `npm run format:js` to only format JavaScript/TypeScript sources539  - `npm run format:md` to only format Markdown files540- `npm run build` to build type declarations and distribution bundles, then fix and clean up generated types541  - `npm run build:types` to only emit TypeScript declaration files542  - `npm run build:rollup` to build all Rollup bundles543  - `npm run build:umd` to only build an unminified UMD bundle544  - `npm run build:umd:min` to only build a minified UMD bundle545  - `npm run build:es` to only build the ES module bundle546  - `npm run build:cjs` to only build the CommonJS bundle547  - `npm run build:fix-types` to post-process generated type files548  - `npm run build:cleanup` to clean up temporary generated type output549- `npm run verify-typescript` to run the TypeScript verification script550- `npm run commit-amend-build` to run the maintainer helper script for amending build output551 552Note: all run scripts triggered via `npm run <script>`.553 554There are more npm scripts but they are mainly to integrate with CI or are meant to be "private" for instance to amend build distribution files with every commit.555 556## Security Mailing List557 558We maintain a mailing list that notifies whenever a **security-critical** release of DOMPurify was published. This means, if someone found a bypass and we fixed it with a release (which always happens when a bypass was found) a mail will go out to that list. This usually happens within minutes or a few hours after learning about a bypass. The list can be subscribed to here:559 560[https://lists.ruhr-uni-bochum.de/mailman/listinfo/dompurify-security](https://lists.ruhr-uni-bochum.de/mailman/listinfo/dompurify-security)561 562Feature releases will not be announced to this list.563 564## Who contributed?565 566Many people have helped DOMPurify become what it is today, and they deserve to be acknowledged!567 568[offset](https://github.com/offset), [Bankde](https://github.com/Bankde), [lukewarlow](https://github.com/lukewarlow), [DEMON1A](https://github.com/DEMON1A), [fg0x0](https://github.com/fg0x0), [kodareef5](https://github.com/kodareef5), [DavidOliver](https://github.com/DavidOliver), [1Jesper1](https://github.com/1Jesper1), [bencalif](https://github.com/bencalif), [trace37labs](https://github.com/trace37labs), [eddieran](https://github.com/eddieran), [christos-eth](https://github.com/christos-eth), [researchatfluidattacks](https://github.com/researchatfluidattacks), [frevadiscor](https://github.com/frevadiscor), [Rotzbua](https://github.com/Rotzbua), [binhpv](https://github.com/binhpv), [MariusRumpf](https://github.com/MariusRumpf), [prasadrajandran](https://github.com/prasadrajandran), [Cybozu 💛💸](https://github.com/cybozu), [hata6502 💸](https://github.com/hata6502), [openclaw 💸](https://github.com/openclaw), [intra-mart-dh 💸](https://github.com/intra-mart-dh), [nelstrom ❤️](https://github.com/nelstrom), [hash_kitten ❤️](https://twitter.com/hash_kitten), [kevin_mizu ❤️](https://twitter.com/kevin_mizu), [icesfont ❤️](https://github.com/icesfont), [reduckted ❤️](https://github.com/reduckted), [dcramer 💸](https://github.com/dcramer), [JGraph 💸](https://github.com/jgraph), [baekilda 💸](https://github.com/baekilda), [Healthchecks 💸](https://github.com/healthchecks), [Sentry 💸](https://github.com/getsentry), [jarrodldavis 💸](https://github.com/jarrodldavis), [CynegeticIO](https://github.com/CynegeticIO), [ssi02014 ❤️](https://github.com/ssi02014), [GrantGryczan](https://github.com/GrantGryczan), [Lowdefy](https://twitter.com/lowdefy), [granlem](https://twitter.com/MaximeVeit), [oreoshake](https://github.com/oreoshake), [tdeekens ❤️](https://github.com/tdeekens), [peernohell ❤️](https://github.com/peernohell), [is2ei](https://github.com/is2ei), [SoheilKhodayari](https://github.com/SoheilKhodayari), [franktopel](https://github.com/franktopel), [NateScarlet](https://github.com/NateScarlet), [neilj](https://github.com/neilj), [fhemberger](https://github.com/fhemberger), [Joris-van-der-Wel](https://github.com/Joris-van-der-Wel), [ydaniv](https://github.com/ydaniv), [terjanq](https://twitter.com/terjanq), [filedescriptor](https://github.com/filedescriptor), [ConradIrwin](https://github.com/ConradIrwin), [gibson042](https://github.com/gibson042), [choumx](https://github.com/choumx), [0xSobky](https://github.com/0xSobky), [styfle](https://github.com/styfle), [koto](https://github.com/koto), [tlau88](https://github.com/tlau88), [strugee](https://github.com/strugee), [oparoz](https://github.com/oparoz), [mathiasbynens](https://github.com/mathiasbynens), [edg2s](https://github.com/edg2s), [dnkolegov](https://github.com/dnkolegov), [dhardtke](https://github.com/dhardtke), [wirehead](https://github.com/wirehead), [thorn0](https://github.com/thorn0), [styu](https://github.com/styu), [mozfreddyb ❤️](https://github.com/mozfreddyb), [mikesamuel](https://github.com/mikesamuel), [jorangreef](https://github.com/jorangreef), [jimmyhchan](https://github.com/jimmyhchan), [jameydeorio](https://github.com/jameydeorio), [jameskraus](https://github.com/jameskraus), [hyderali](https://github.com/hyderali), [hansottowirtz](https://github.com/hansottowirtz), [hackvertor](https://github.com/hackvertor), [freddyb](https://github.com/freddyb), [flavorjones](https://github.com/flavorjones), [djfarrelly](https://github.com/djfarrelly), [devd](https://github.com/devd), [camerondunford](https://github.com/camerondunford), [buu700](https://github.com/buu700), [buildog](https://github.com/buildog), [alabiaga](https://github.com/alabiaga), [Vector919](https://github.com/Vector919), [Robbert](https://github.com/Robbert), [GreLI](https://github.com/GreLI), [FuzzySockets](https://github.com/FuzzySockets), [ArtemBernatskyy](https://github.com/ArtemBernatskyy), [@garethheyes](https://twitter.com/garethheyes), [@shafigullin](https://twitter.com/shafigullin), [@mmrupp](https://twitter.com/mmrupp), [@irsdl](https://twitter.com/irsdl),[ShikariSenpai](https://github.com/ShikariSenpai), [ansjdnakjdnajkd](https://github.com/ansjdnakjdnajkd), [@asutherland](https://twitter.com/asutherland), [@mathias](https://twitter.com/mathias), [@cgvwzq](https://twitter.com/cgvwzq), [@robbertatwork](https://twitter.com/robbertatwork), [@giutro](https://twitter.com/giutro), [@CmdEngineer\_](https://twitter.com/CmdEngineer_), [@avr4mit](https://twitter.com/avr4mit), [davecardwell](https://github.com/davecardwell), [Develop-KIM](https://github.com/Develop-KIM), [asamuzaK](https://github.com/asamuzaK), [fishjojo1](https://github.com/fishjojo1), [Rikuxx0](https://github.com/Rikuxx0) and especially [@securitymb ❤️](https://twitter.com/securitymb) & [@masatokinugawa ❤️](https://twitter.com/masatokinugawa)569 
Brunobkr/llama.cpp_AlgMor24_github · Team Ai