@rtorcato/js-common / html
html
Functions
escapeHtml()
escapeHtml(
str):string
Defined in: html/index.ts:14
Escapes special HTML characters in a string to prevent XSS attacks.
Example
escapeHtml('<script>alert("x")</script>')
// '<script>alert("x")</script>'
escapeHtml("Tom & Jerry's") // 'Tom & Jerry's'
Parameters
str
string
The string to escape.
Returns
string
The escaped string.
unescapeHtml()
unescapeHtml(
str):string
Defined in: html/index.ts:36
Unescapes HTML entities in a string.
Example
unescapeHtml('<b>hi</b>') // '<b>hi</b>'
unescapeHtml('Tom & Jerry') // 'Tom & Jerry'
unescapeHtml('a/b c') // 'a/b c'
Parameters
str
string
The string to unescape.
Returns
string
The unescaped string.
stripHtmlTags()
stripHtmlTags(
str):string
Defined in: html/index.ts:91
Strips all HTML tags from a string.
Example
stripHtmlTags('<p>Hello <b>world</b></p>') // 'Hello world'
stripHtmlTags('plain text') // 'plain text'
// Strips `<…>` spans, so ragged input leaves residue — not a sanitizer.
stripHtmlTags('<<a>script>') // 'script>'
stripHtmlTags('<scr<x>ipt>') // 'ipt>'
Removes <…> spans and nothing else: it does not decode entities and does
not understand attributes or quoting, so ragged or nested markup leaves
attacker-controlled residue behind rather than a safe string. Not a
substitute for a real sanitizer such as DOMPurify when rendering untrusted
HTML — this produces display text, it does not make untrusted markup safe.
Parameters
str
string
The string to strip tags from.
Returns
string
The plain text string.
textToHtml()
textToHtml(
str):string
Defined in: html/index.ts:106
Converts a plain text string to a simple HTML paragraph (newlines become <br> tags).
Parameters
str
string
The plain text string.
Returns
string
The HTML string with <br> tags.
containsHtml()
containsHtml(
str):boolean
Defined in: html/index.ts:120
Checks if a string contains any HTML tags.
A heuristic for "does this look like markup", not a security gate: it only
looks for a non-empty <…> span, so 'a<b' and '<>' are both false. Do
not use it to decide whether untrusted input is safe to render.
Parameters
str
string
The string to check.
Returns
boolean
True if the string contains HTML tags, false otherwise.