/**
* Trusted Types helpers for CSP compatibility.
*
* @module bquery/security
*/
import type { TrustedHTML, TrustedTypePolicy } from './types.cjs';
/**
* Check if Trusted Types API is available.
* @returns True if Trusted Types are supported
*/
export declare const isTrustedTypesSupported: () => boolean;
/**
* Get or create the bQuery Trusted Types policy.
* @returns The Trusted Types policy or null if unsupported
*/
export declare const getTrustedTypesPolicy: () => TrustedTypePolicy | null;
/**
* Create a Trusted HTML value for use with Trusted Types-enabled sites.
* Falls back to regular string when Trusted Types are unavailable.
*
* @param html - The HTML string to wrap
* @returns Trusted HTML value or sanitized string
*/
export declare const createTrustedHtml: (html: string) => TrustedHTML | string;
/**
* Returns the value to assign to an HTML sink (`innerHTML` /
* `insertAdjacentHTML`). When a Trusted Types policy is active the value is a
* `TrustedHTML` object, so the write satisfies an enforced
* `require-trusted-types-for 'script'` CSP instead of throwing; otherwise it is
* the sanitized string. Sanitizes exactly once.
*
* The declared return type is `string` for ergonomic assignment to DOM sink
* setters (whose lib types expect `string`); at runtime under enforced Trusted
* Types the returned value is the `TrustedHTML` object the browser accepts.
*
* @example
* ```ts
* // Safe under an enforced `require-trusted-types-for 'script'` CSP.
* element.innerHTML = trustedHtmlForSink('Hello');
* ```
*/
export declare const trustedHtmlForSink: (rawHtml: string) => string;
/**
* Returns a sink-assignable value for markup that must **not** be sanitized
* again: output bQuery already sanitized with a caller-specific allow list
* (component render output keeps ``, `part`, form attributes), or an
* author-controlled template (`createTemplate()`), which the documented
* threat model treats as trusted. The DOM sanitizer backend also uses it to
* hand its input to `DOMParser.parseFromString` (itself a Trusted Types sink),
* since the parsed document is inert and only reaches callers after the
* allow lists have run.
*
* Assigning such a string straight to `innerHTML` throws under an enforced
* `require-trusted-types-for 'script'` CSP, while routing it through
* {@link trustedHtmlForSink} would re-sanitize it with the default allow
* list and strip what the caller deliberately kept. This wraps it through
* the same `bquery-sanitizer` policy — so no extra policy name has to be
* allowed in the CSP — without a second sanitizer pass. Without Trusted
* Types it returns the string unchanged.
*
* Never pass untrusted input here: this function performs no sanitization.
* @internal
*/
export declare const trustedPreparedHtmlForSink: (preparedHtml: string) => string;
/**
* Forget the cached policy so the next sink write re-detects Trusted Types.
* Test-only: browsers never let a page remove `window.trustedTypes`.
* @internal
*/
export declare const __resetTrustedTypesPolicy: () => void;
//# sourceMappingURL=trusted-types.d.ts.map