Sha256: 07541c9e0f3973d5ed1acef8c6834a0cfd05c36990e645dd80c202323fae038b

Contents?: true

Size: 1.18 KB

Versions: 1

Compression:

Stored size: 1.18 KB

Contents

require 'sanitize'

module Softcover
  module Sanitizer
    extend self

    # Sanitization suitable for displaying untrusted generated html, while
    # retaining useful tags and attributes.

    def clean(html)
      return unless html

      sanitize_options = {
        elements: %w{div span p a ul ol li h1 h2 h3 h4
          pre em sup table tbody thead tr td img},
        remove_contents: %w{script},
        attributes: {
          'div' => %w{id class data-tralics-id data-number data-chapter},
          'a'   => %w{id class href},
          'span'=> %w{id class style},
          'ol'  => %w{id class},
          'ul'  => %w{id class},
          'li'  => %w{id class},
          'sup' => %w{id class},
          'h1'  => %w{id class},
          'h2'  => %w{id class},
          'h3'  => %w{id class},
          'h4'  => %w{id class},
          'img' => %w{id class src alt},
          'em'  => %w{id class}
        },
        protocols: {
          'a'   => {'href' => [:relative, 'http', 'https', 'mailto']},
          'img' => {'src'  => [:relative, 'http', 'https']}
        },
        output: :xhtml
      }

      Sanitize.clean(html.force_encoding("UTF-8"), sanitize_options)
    end
  end
end

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
softcover-0.7.2 lib/softcover/sanitizer.rb