Sha256: 0802528212297a0340a492d62f094cc0709a562de837ff007ccbe9dcf53851e6

Contents?: true

Size: 1.29 KB

Versions: 5

Compression:

Stored size: 1.29 KB

Contents

class Sanitize; module Transformers; module CSS

# Enforces a CSS allowlist on the contents of `style` attributes.
class CleanAttribute
  def initialize(sanitizer_or_config)
    if Sanitize::CSS === sanitizer_or_config
      @scss = sanitizer_or_config
    else
      @scss = Sanitize::CSS.new(sanitizer_or_config)
    end
  end

  def call(env)
    node = env[:node]

    return unless node.type == Nokogiri::XML::Node::ELEMENT_NODE &&
        node.key?('style') && !env[:is_allowlisted]

    attr = node.attribute('style')
    css  = @scss.properties(attr.value)

    if css.strip.empty?
      attr.unlink
    else
      attr.value = css
    end
  end
end

# Enforces a CSS allowlist on the contents of `<style>` elements.
class CleanElement
  def initialize(sanitizer_or_config)
    if Sanitize::CSS === sanitizer_or_config
      @scss = sanitizer_or_config
    else
      @scss = Sanitize::CSS.new(sanitizer_or_config)
    end
  end

  def call(env)
    node = env[:node]

    return unless node.type == Nokogiri::XML::Node::ELEMENT_NODE &&
        env[:node_name] == 'style'

    css = @scss.stylesheet(node.content)

    if css.strip.empty?
      node.unlink
    else
      css.gsub!('</', '<\/')
      node.children.unlink
      node << Nokogiri::XML::Text.new(css, node.document)
    end
  end
end

end; end; end

Version data entries

5 entries across 5 versions & 1 rubygems

Version Path
sanitize-6.1.3 lib/sanitize/transformers/clean_css.rb
sanitize-6.1.2 lib/sanitize/transformers/clean_css.rb
sanitize-6.1.1 lib/sanitize/transformers/clean_css.rb
sanitize-6.1.0 lib/sanitize/transformers/clean_css.rb
sanitize-6.0.2 lib/sanitize/transformers/clean_css.rb