1.0.2 • Published 3 years ago
html-serialization v1.0.2
HTML Serialization
测试库, XSS filter
const $app = document.getElementById('app')!
const template = `<div><script>document.write('xss')</script></div><a href="javascript:;" ></a>`
$app.innerHTML = template
$app.replaceWith(HTMLFilter($app, { skipTags: ['script'], encodeTags: [] }))
console.log(HTMLDeserialization(template))
console.log(HTMLStringFilter(template))