export type InsertAdjacentHtmlPosition = string; export namespace InsertAdjacentHtmlPosition { const AFTERBEGIN: string; const AFTEREND: string; const BEFOREBEGIN: string; const BEFOREEND: string; } /** * Safely assigns the URL of a Location object. * * If url is of type Html_SafeUrl, its value is unwrapped and * passed to Location#assign. If url is of type string however, it is * first sanitized using Html_SafeUrl.sanitize. * * Example usage: * assignLocation(document.location, newUrl); * which is a safe alternative to * document.location.assign(newUrl); * The latter can result in XSS vulnerabilities if newUrl is a * user-/attacker-controlled value. * * This has the same behaviour as setLocationHref, however some test * mock Location.assign instead of a property assignment. * * @param {!Location} loc The Location object which is to be assigned. * @param {string|!Html_SafeUrl} url The URL to assign. * @return {void} * @see Html_SafeUrl#sanitize */ export function assignLocation(loc: Location, url: string | Html_SafeUrl): void; /** * Creates a DocumentFragment by parsing html in the context of a Range. * @param {!Range} range The Range object starting from the context node to * create a fragment in. * @param {!Html_SafeHtml} html HTML to create a fragment from. * @return {?DocumentFragment} */ export function createContextualFragment(range: Range, html: Html_SafeHtml): DocumentFragment | null; /** * Safely creates an HTMLImageElement from a Blob. * * Example usage: * createImageFromBlob(blob); * which is a safe alternative to * image.src = createObjectUrl(blob) * The latter can result in executing malicious same-origin scripts from a bad * Blob. * @param {!Blob} blob The blob to create the image from. * @return {!HTMLImageElement} The image element created from the blob. * @throws {!Error} If called with a Blob with a MIME type other than image/.*. */ export function createImageFromBlob(blob: Blob): HTMLImageElement; /** * Writes known-safe HTML to a document. * @param {!Document} doc The document to be written to. * @param {!Html_SafeHtml} html The known-safe HTML to assign. * @return {void} */ export function documentWrite(doc: Document, html: Html_SafeHtml): void; /** * Returns CSP script nonce, if set for any