import type { HotInstance } from '../core/types'; import type { SanitizerContext, SanitizerFn } from '../core/settings'; /** * Re-exported for the plugins that hold a resolved sanitizer (`dialog`, `notification`). * * Treat this as reachable by consumers, not sealed. The published `exports` map has no `./utils/*` * entry, but that only blocks subpath resolution under `node16` and `bundler`; classic * `moduleResolution: node` ignores `exports` entirely, and `tmp/utils/sanitizer.d.ts` is shipped * with no `files` field trimming it. So renaming or narrowing what this module exports can break a * consumer. `SanitizerContext` is published from `handsontable` itself, which is where users should * take it from. */ export type { SanitizerFn } from '../core/settings'; /** * Reads the grid-level `sanitizer` option in the form `fastInnerHTML` expects. * * Every call site that writes cell or header content through `fastInnerHTML` goes through this * helper, so they cannot drift apart on the fallback value or on how the option is looked up. * `true` is the fallback, which makes `fastInnerHTML` write raw HTML and warn once. * * The `html` cell type and `allowHtml` autocomplete sources deliberately do not use this helper: * they render raw HTML by design (see PR #7368) and pass `false` instead. * * @param {object} hot The Handsontable instance. * @returns {boolean|Function} The configured sanitizer, or `true` when none is set. */ export declare function getSanitizer(hot: HotInstance): boolean | SanitizerFn; /** * Sanitizes an HTML string for surfaces that build markup as a string instead of writing it * into an element through `fastInnerHTML` — the clipboard paste path and the nested-header * ghost table. * * A configured sanitizer sees every payload, markup or not, which is what the clipboard path has * always done. Only the missing-sanitizer warning is gated on markup. A caller that must match * `fastInnerHTML` exactly, where plain text never reaches the sanitizer at all, has to apply that * test itself before calling this. The nested-header ghost table does, so the label it measures is * treated the same way as the header that renders it. * * The warning is bound to `hot.rootElement`, the scope every other surface uses, so all of them * collapse into a single message per Handsontable instance. * * @param {object} hot The Handsontable instance. * @param {string} html The HTML string to sanitize. * @param {SanitizerContext} context The write surface, passed to the sanitizer and named in the warning. * @returns {string} The sanitized string, or the input unchanged when no sanitizer is configured. */ export declare function sanitizeHTML(hot: HotInstance, html: string, context: SanitizerContext): string;