Files
nobat724_front/lib/sanitize.js
T

34 lines
1.3 KiB
JavaScript

import DOMPurify from "isomorphic-dompurify";
export function sanitizeHtml(html) {
if (!html || typeof html !== "string") return "";
// ⚠️ ALLOWED_TAGS اینجا با `clinicpro-crawler/content/composer.py` (ثابت
// ALLOWED_TAGS) آینه است: مولد محتوا فقط همین تگ‌ها را تولید می‌کند. اگر این
// فهرست را تغییر دادی، آن‌جا را هم تغییر بده — وگرنه محتوای تولیدشده بی‌صدا
// از صفحه حذف می‌شود. توجه: class و style در ALLOWED_ATTR نیستند.
return DOMPurify.sanitize(html, {
ALLOWED_TAGS: [
"p", "br", "strong", "em", "b", "i", "u", "ul", "ol", "li", "a",
"h2", "h3", "h4", "h5", "blockquote", "img", "span", "div",
"table", "thead", "tbody", "tr", "td", "th",
],
ALLOWED_ATTR: ["href", "target", "rel", "src", "alt", "title"],
ALLOW_DATA_ATTR: false,
});
}
// خروجی امن برای <script type="application/ld+json"> — جلوگیری از بستن تگ با داده‌ی کاربر
export function safeJsonLd(obj) {
return JSON.stringify(obj).replace(/</g, "\\u003c");
}
export function safeJsonParse(str, fallback = null) {
if (!str) return fallback;
try {
return JSON.parse(str);
} catch {
return fallback;
}
}