-
Notifications
You must be signed in to change notification settings - Fork 955
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add trusted types support to lit html
- Loading branch information
Emanuel Tesar
committed
Jul 29, 2019
1 parent
6f2bf43
commit a3677e5
Showing
6 changed files
with
145 additions
and
16 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,43 @@ | ||
function getTrustedTypes() { | ||
// tslint:disable-next-line | ||
return (window as any).TrustedTypes; | ||
} | ||
|
||
const rules = { | ||
createHTML(s: string): string { | ||
return s; | ||
}, | ||
}; | ||
let policy: typeof rules | undefined; | ||
|
||
/** | ||
* Turns the value to trusted HTML. If the application uses Trusted Types the value is transformed into TrustedHTML, | ||
* which can be assigned to execution sink. If the application doesn't use Trusted Types, the return value is the same | ||
* as the argument. | ||
*/ | ||
export function dangerouslyTurnToTrustedHTML(value: string): string { | ||
const TrustedTypes = getTrustedTypes(); | ||
if (!policy && TrustedTypes !== undefined) { | ||
policy = TrustedTypes.createPolicy('lit-html', rules); | ||
} | ||
|
||
if (!policy) { | ||
return value; | ||
} else { | ||
return policy.createHTML(value); | ||
} | ||
} | ||
|
||
/** | ||
* Checks whether the value is a Trusted Types object instance. | ||
*/ | ||
export function isTrustedValue(value: unknown): boolean { | ||
const TrustedTypes = getTrustedTypes(); | ||
if (TrustedTypes === undefined) return false; | ||
else { | ||
return TrustedTypes.isHTML(value) || | ||
TrustedTypes.isScriptURL(value) || | ||
TrustedTypes.isURL(value) || | ||
TrustedTypes.isScript(value); | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,66 @@ | ||
/** | ||
* @license | ||
* Copyright (c) 2019 The Polymer Project Authors. All rights reserved. | ||
* This code may only be used under the BSD style license found at | ||
* http://polymer.github.io/LICENSE.txt | ||
* The complete set of authors may be found at | ||
* http://polymer.github.io/AUTHORS.txt | ||
* The complete set of contributors may be found at | ||
* http://polymer.github.io/CONTRIBUTORS.txt | ||
* Code distributed by Google as part of the polymer project is also | ||
* subject to an additional IP rights grant found at | ||
* http://polymer.github.io/PATENTS.txt | ||
*/ | ||
|
||
import {render} from '../../lib/shady-render.js'; | ||
import {html} from '../../lit-html.js'; | ||
import {unsafeHTML} from '../../directives/unsafe-html'; | ||
|
||
const assert = chai.assert; | ||
|
||
suite('rendering with trusted types enforced', () => { | ||
let container: HTMLDivElement; | ||
|
||
suiteSetup(() => { | ||
// tslint:disable-next-line | ||
(window as any).TrustedTypes = { | ||
isHTML: () => true, | ||
createPolicy: () => { | ||
createHTML: (value: string) => `TRUSTED${value}`; | ||
}, | ||
isScript: () => false, | ||
isScriptURL: () => false, | ||
isURL: () => false, | ||
}; | ||
|
||
// simulate trusted types enforcement in a browser | ||
Object.defineProperty(HTMLElement.prototype, 'innerHTML', {set: function(value: string) { | ||
// lit-html internally calls dangerouslyTurnToTrustedHTML with '<!--{{uniqueId}}-->' | ||
if (value.startsWith('<!--{{lit-')) this.prototype.innerHTML = value; | ||
else if (value.startsWith('TRUSTED')) this.prototype.innerHTML = value.substr('TRUSTED'.length); | ||
else throw new Error(value); | ||
}}); | ||
|
||
// create app root in the DOM | ||
container = document.createElement('div'); | ||
document.body.appendChild(container); | ||
}); | ||
|
||
suiteTeardown(() => { | ||
delete HTMLElement.prototype.innerHTML; | ||
}); | ||
|
||
test('throws when value is not trusted type', () => { | ||
const result = html`${unsafeHTML('<b>unsafe bold</b>')}`; | ||
assert.throws(() => { | ||
render(result, container, {scopeName: 'div'}); | ||
}); | ||
}); | ||
|
||
test('passes when value is trusted type', () => { | ||
const result = html`${unsafeHTML('TRUSTED<b>unsafe bold</b>')}`; | ||
assert.throws(() => { | ||
render(result, container, {scopeName: 'div'}); | ||
}); | ||
}); | ||
}); |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,12 @@ | ||
<!doctype html> | ||
<html> | ||
<head> | ||
<script src="../node_modules/mocha/mocha.js"></script> | ||
<script src="../node_modules/chai/chai.js"></script> | ||
<script src="../node_modules/wct-mocha/wct-mocha.js"></script> | ||
<script src="../node_modules/@webcomponents/webcomponentsjs/webcomponents-bundle.js"></script> | ||
</head> | ||
<body> | ||
<script type="module" src="./lib/trusted-types_test.js"></script> | ||
</body> | ||
</html> |