/*! * Jodit Editor (https://xdsoft.net/jodit/) * Released under MIT see LICENSE.txt in the project root for license information. * Copyright (c) 2013-2026 Valerii Chupurnov. All rights reserved. https://xdsoft.net */ /** * @module plugins/clean-html */ import type { HTMLTagNames, IDictionary, Nullable } from "../../types/index"; declare module 'jodit/config' { interface Config { cleanHTML: { timeout: number; /** * Replace   to plain space */ replaceNBSP: boolean; /** * Remove empty P tags, if they are not in the beginning of the text */ fillEmptyParagraph: boolean; /** * Remove empty inline elements. Elements that in-page links can point * at (anything with an `id`, and `` with a `name`) are kept. */ removeEmptyElements: boolean; /** * Return an empty string from `editor.value` (and the synced source * element) when the editor holds only a single empty block — e.g. * `


` left after the user deletes all the content. * `contenteditable` keeps that caret container in the DOM, so by * default the value getter returns it as-is; enable this to collapse * it to `''` for form submission. */ collapseEmptyValueToEmptyString: boolean; /** * Browsers serialise quoted font names in a `style` attribute with * double quotes, which end up as `"` in the editor value * (`font-family: "Open Sans", sans-serif`). Some back ends * HTML-decode the value before storing it and turn that into invalid * markup. With this option (default) the value getter rewrites such * names with single quotes: `font-family: 'Open Sans', sans-serif`. */ singleQuotesInFontFamily: boolean; /** * Browsers keep a trailing `
` inside a block after you type into an * empty one (`

test

`), and the same `
` ends up in the * editor value. It renders nothing, but confuses consumers that compare * or post-process the HTML. With this option the value getter drops a * `
` that is the last node of a block (or of the whole value) * and follows other content. `


` and `text

` — an empty * line — are kept. */ removeTrailingBr: boolean; /** * Replace old tags to new eg. to , to */ replaceOldTags: IDictionary | false; /** * You can use an iframe with the sandbox attribute to safely paste and test HTML code. * It prevents scripts and handlers from running, but it does slow things down. * * ```javascript * Jodit.make('#editor', { * cleanHTML: { * useIframeSandbox: true * } * }); * ``` */ useIframeSandbox: boolean; /** * @deprecated Use `removeEventAttributes` instead * Remove onError attributes */ removeOnError: boolean; /** * Remove all `on*` event handler attributes (onerror, onclick, onload, onmouseover, etc.) * When enabled, this replaces the legacy `removeOnError` behavior with comprehensive protection. * * ```javascript * Jodit.make('#editor', { * cleanHTML: { * removeEventAttributes: true * } * }); * ``` */ removeEventAttributes: boolean; /** * Safe href="javascript:" links */ safeJavaScriptLink: boolean; /** * Automatically add `rel="noopener noreferrer"` to links with `target="_blank"` * * ```javascript * Jodit.make('#editor', { * cleanHTML: { * safeLinksTarget: true * } * }); * ``` */ safeLinksTarget: boolean; /** * Whitelist of allowed CSS properties inside `style` attributes. * If set, all CSS properties not in the list will be removed. * * ```javascript * Jodit.make('#editor', { * cleanHTML: { * allowedStyles: { * '*': ['color', 'background-color', 'font-size', 'text-align'], * img: ['width', 'height'] * } * } * }); * ``` */ allowedStyles: false | IDictionary; /** * Custom sanitizer function. Called after Jodit's built-in sanitization. * Use this to integrate DOMPurify or other external sanitizers. * * ```javascript * import DOMPurify from 'dompurify'; * * Jodit.make('#editor', { * cleanHTML: { * sanitizer: (html) => DOMPurify.sanitize(html) * } * }); * ``` */ sanitizer: false | ((value: string) => string); /** * Automatically add `sandbox=""` attribute to all `