/** * Trusted Types helpers for CSP compatibility. * * @module bquery/security */ import type { TrustedHTML, TrustedTypePolicy } from './types.cjs'; /** * Check if Trusted Types API is available. * @returns True if Trusted Types are supported */ export declare const isTrustedTypesSupported: () => boolean; /** * Get or create the bQuery Trusted Types policy. * @returns The Trusted Types policy or null if unsupported */ export declare const getTrustedTypesPolicy: () => TrustedTypePolicy | null; /** * Create a Trusted HTML value for use with Trusted Types-enabled sites. * Falls back to regular string when Trusted Types are unavailable. * * @param html - The HTML string to wrap * @returns Trusted HTML value or sanitized string */ export declare const createTrustedHtml: (html: string) => TrustedHTML | string; /** * Returns the value to assign to an HTML sink (`innerHTML` / * `insertAdjacentHTML`). When a Trusted Types policy is active the value is a * `TrustedHTML` object, so the write satisfies an enforced * `require-trusted-types-for 'script'` CSP instead of throwing; otherwise it is * the sanitized string. Sanitizes exactly once. * * The declared return type is `string` for ergonomic assignment to DOM sink * setters (whose lib types expect `string`); at runtime under enforced Trusted * Types the returned value is the `TrustedHTML` object the browser accepts. * * @example * ```ts * // Safe under an enforced `require-trusted-types-for 'script'` CSP. * element.innerHTML = trustedHtmlForSink('Hello'); * ``` */ export declare const trustedHtmlForSink: (rawHtml: string) => string; /** * Returns a sink-assignable value for markup that must **not** be sanitized * again: output bQuery already sanitized with a caller-specific allow list * (component render output keeps ``, `part`, form attributes), or an * author-controlled template (`createTemplate()`), which the documented * threat model treats as trusted. The DOM sanitizer backend also uses it to * hand its input to `DOMParser.parseFromString` (itself a Trusted Types sink), * since the parsed document is inert and only reaches callers after the * allow lists have run. * * Assigning such a string straight to `innerHTML` throws under an enforced * `require-trusted-types-for 'script'` CSP, while routing it through * {@link trustedHtmlForSink} would re-sanitize it with the default allow * list and strip what the caller deliberately kept. This wraps it through * the same `bquery-sanitizer` policy — so no extra policy name has to be * allowed in the CSP — without a second sanitizer pass. Without Trusted * Types it returns the string unchanged. * * Never pass untrusted input here: this function performs no sanitization. * @internal */ export declare const trustedPreparedHtmlForSink: (preparedHtml: string) => string; /** * Forget the cached policy so the next sink write re-detects Trusted Types. * Test-only: browsers never let a page remove `window.trustedTypes`. * @internal */ export declare const __resetTrustedTypesPolicy: () => void; //# sourceMappingURL=trusted-types.d.ts.map