/** * Shared output-sanitization helpers. * * Every string in the parsed AST originates from an untrusted document, so any * value interpolated into generated output (HTML, XHTML, CSS, URLs, inline * scripts, CSV, RTF, Markdown) must be escaped for its destination context. * These are the single source of truth — each generator delegates to them so * escaping stays consistent and a gap fixed here is fixed everywhere. */ /** * Whether a string is a plain HTML attribute *name*, safe to interpolate before `="..."`. * * Escaping the value is not enough on its own: a key containing a quote or `=` closes the * attribute and opens another, so `x" onmouseover="alert(1)" z` yields a real event handler no * matter how carefully the value is escaped. This is the shape an attribute-injection payload * takes, and rejecting it outright is simpler and safer than trying to escape a name. * * The predicate is shared rather than restated because it is now applied at four independent * points (the parser's attribute collection, the generator's attribute bag, and two * styleMap-driven paths). Each of those still keeps its own skip-list inline: the lists are the * same policy expressed for different layers, and collapsing them would erase the defence in * depth the surrounding comments describe. */ export declare function isSafeHtmlAttributeName(name: string): boolean; /** * Whether a `styleMap` `output.tag` may be emitted as an element name. * * Callers must fall back to their default tag when this returns false, never emit the value. */ export declare function isSafeStyleMapTag(tag: unknown): tag is string; /** * Escapes text for an HTML text node or a double-quoted attribute value. * Includes the single quote so the result is also safe inside single-quoted * attributes. */ export declare function escapeHtml(text: string): string; /** * Escapes text for an XML text node or attribute (XHTML/OPF/NCX). Same as * escapeHtml but emits the XML-canonical `'` for the single quote. */ export declare function escapeXml(text: string): string; /** * Sanitizes a single CSS value (e.g. a color/size/font/alignment pulled from a * document) for placement inside a `style="prop: VALUE"` attribute. * * - Drops the whole value if it contains a resource-fetching or executing * construct (`url()`, `expression()`, `@import`, `image-set()`, `javascript:`) * or angle brackets that could break out of the attribute/tag. * - Strips characters that break out of `prop: value` (`;`, quotes), out of a * `