/
home
/
techb158
/
public_html
/
wp-content
/
plugins
/
elementor
/
assets
/
js
/
/home/techb158/public_html/wp-content/plugins/elementor/assets/js
mkdir
upload
Name
Size
Mode
Actions
packages/
-
0755
rm
0bc41c4656ca54cf2aca.bundle.min.js
169
0666
edit
dl
rm
1e658f1f0d7790a8e5d5.bundle.js
1855
0666
edit
dl
rm
2bac2875cdf51a1f8140.bundle.min.js
664
0666
edit
dl
rm
3c838288a9b7ddd2aea4.bundle.min.js
578
0666
edit
dl
rm
3d410a099008411bb011.bundle.js
63375
0666
edit
dl
rm
4c96eab5a48ee097dcb2.bundle.js
1794
0666
edit
dl
rm
4da0f59f644453c5778f.bundle.js
1816
0666
edit
dl
rm
4fba6dc68de19bf14ed6.bundle.min.js
1480
0666
edit
dl
rm
5b575dffd21b0cec15a5.bundle.js
1074
0666
edit
dl
rm
6a19e86dd8c1f9165dbe.bundle.js
44901
0666
edit
dl
rm
6caa76d2f6eec6c4e665.bundle.js
64411
0666
edit
dl
rm
06dbd869189450c5db6c.bundle.js
5971
0666
edit
dl
rm
7dae73b622bebe8a5d94.bundle.js
643
0666
edit
dl
rm
7f03d97d8f12b0e62c20.bundle.min.js
1360
0666
edit
dl
rm
8ad22e7ba800b096313c.bundle.min.js
5221
0666
edit
dl
rm
8c20eb5e96967d3016b2.bundle.js
5114
0666
edit
dl
rm
8c595e27c4832221c639.bundle.min.js
1314
0666
edit
dl
rm
8e8b47ad5b4e4d038c80.bundle.js
636
0666
edit
dl
rm
8ecfd8495b7ec419862a.bundle.js
613
0666
edit
dl
rm
9aabe8efbe6be85f9b03.bundle.js
1876
0666
edit
dl
rm
9b0cc3aa93cf287cd0a2.bundle.min.js
607
0666
edit
dl
rm
9dcd9e88237da6496816.bundle.min.js
114
0666
edit
dl
rm
9ffe53753902b9aca176.bundle.js
5081
0666
edit
dl
rm
14bcbc91620c14a7112c.bundle.min.js
4616
0666
edit
dl
rm
24dc90de724d8d2211e7.bundle.js
1887
0666
edit
dl
rm
29c342e9c10e3f13f498.bundle.js
5733
0666
edit
dl
rm
40d841f4b4ce7b1928f5.bundle.js
1030
0666
edit
dl
rm
73f63f9507c306870586.bundle.min.js
4849
0666
edit
dl
rm
77b60be7dc925a32f560.bundle.min.js
696
0666
edit
dl
rm
87abe5f6e10f360edaa2.bundle.min.js
1400
0666
edit
dl
rm
220e9c3d1caa01726b1a.bundle.js
5427
0666
edit
dl
rm
397f2d183c19202777d6.bundle.min.js
23933
0666
edit
dl
rm
397f2d183c19202777d6.bundle.min.js.LICENSE.txt
188
0666
edit
dl
rm
425e7653a6beca0ca547.bundle.min.js
6841
0666
edit
dl
rm
463aee37e06b67916b81.bundle.js
1978
0666
edit
dl
rm
481dd84bfd172b56f2c9.bundle.js
66405
0666
edit
dl
rm
620a14a68e8c9da1ef28.bundle.js
7339
0666
edit
dl
rm
733e5d484a31a515a18e.bundle.min.js
1377
0666
edit
dl
rm
831aea236b1ddda24f0c.bundle.js
1121
0666
edit
dl
rm
0982f37bec0944fbcb10.bundle.js
613
0666
edit
dl
rm
1564d2bfa4591bf857f3.bundle.min.js
114
0666
edit
dl
rm
6936b079b4e7c28cd901.bundle.min.js
754
0666
edit
dl
rm
012778ff5828d0d1739f.bundle.js
1148
0666
edit
dl
rm
16864f39793c3475fda1.bundle.min.js
1481
0666
edit
dl
rm
20866d9d9e34bf3cb0a7.bundle.min.js
694
0666
edit
dl
rm
35423d812dc1d52fdb27.bundle.min.js
169
0666
edit
dl
rm
39845c9a7f0477e3323d.bundle.js
1862
0666
edit
dl
rm
59845ab5a628d2b79f57.bundle.js
1111
0666
edit
dl
rm
197583acd246fea0e25d.bundle.js
11222
0666
edit
dl
rm
600430d4fe11ccbb856b.bundle.js
1880
0666
edit
dl
rm
687979ffbcfd58352c29.bundle.min.js
4862
0666
edit
dl
rm
845418a5488e9937fc99.bundle.min.js
4930
0666
edit
dl
rm
8277989eebcfba278cb0.bundle.min.js
36823
0666
edit
dl
rm
65955179c51c059f89dd.bundle.js
1913
0666
edit
dl
rm
6273709440e0031100bc.bundle.min.js
1476
0666
edit
dl
rm
a0f667abb781daab8e48.bundle.js
5359
0666
edit
dl
rm
a9c3d5b02d26399aebfb.bundle.js
1131
0666
edit
dl
rm
aae1dc723585a57c406a.bundle.min.js
31894
0666
edit
dl
rm
accordion.8b0db5058afeb74622f5.bundle.min.js
3739
0666
edit
dl
rm
accordion.b9a0ab19c7c872c405d7.bundle.js
7927
0666
edit
dl
rm
admin-feedback.js
4572
0666
edit
dl
rm
admin-feedback.min.js
1913
0666
edit
dl
rm
admin-feedback.strings.js
1468
0666
edit
dl
rm
admin-modules.js
39944
0666
edit
dl
rm
admin-modules.min.js
15736
0666
edit
dl
rm
admin-modules.min.js.LICENSE.txt
163
0666
edit
dl
rm
admin-modules.strings.js
1468
0666
edit
dl
rm
admin-notifications.js
78124
0666
edit
dl
rm
admin-notifications.min.js
15328
0666
edit
dl
rm
admin-notifications.strings.js
100
0666
edit
dl
rm
admin-top-bar.js
68298
0666
edit
dl
rm
admin-top-bar.min.js
11803
0666
edit
dl
rm
admin-top-bar.strings.js
320
0666
edit
dl
rm
admin.js
197088
0666
edit
dl
rm
admin.min.js
90336
0666
edit
dl
rm
admin.min.js.LICENSE.txt
163
0666
edit
dl
rm
admin.strings.js
1468
0666
edit
dl
rm
aee13673e923469c3275.bundle.min.js
114
0666
edit
dl
rm
af05aac2eb23e7438265.bundle.js
5182
0666
edit
dl
rm
ai-admin.js
1152843
0666
edit
dl
rm
ai-admin.min.js
474627
0666
edit
dl
rm
ai-admin.min.js.LICENSE.txt
163
0666
edit
dl
rm
ai-admin.strings.js
0
0666
edit
dl
rm
ai-form-code.88e99d22c799e35838c3.bundle.min.js
9392
0666
edit
dl
rm
ai-form-code.f1fc9ab9d55b03c0a95d.bundle.js
22741
0666
edit
dl
rm
ai-gutenberg.js
1287417
0666
edit
dl
rm
ai-gutenberg.min.js
503822
0666
edit
dl
rm
ai-gutenberg.min.js.LICENSE.txt
324
0666
edit
dl
rm
ai-gutenberg.strings.js
191
0666
edit
dl
rm
ai-layout.js
544773
0666
edit
dl
rm
ai-layout.min.js
208388
0666
edit
dl
rm
ai-layout.min.js.LICENSE.txt
163
0666
edit
dl
rm
ai-layout.strings.js
21782
0666
edit
dl
rm
ai-media-library.js
1269785
0666
edit
dl
rm
ai-media-library.min.js
498460
0666
edit
dl
rm
ai-media-library.min.js.LICENSE.txt
324
0666
edit
dl
rm
ai-media-library.strings.js
138
0666
edit
dl
rm
ai-react-markdown.6230542471e5145001f3.bundle.min.js
128795
0666
edit
dl
rm
ai-react-markdown.6230542471e5145001f3.bundle.min.js.LICENSE.txt
361
0666
edit
dl
rm
ai-react-markdown.cf9412823b81e9b583aa.bundle.js
818993
0666
edit
dl
rm
ai-unify-product-images.js
1266109
0666
edit
dl
rm
ai-unify-product-images.min.js
495664
0666
edit
dl
rm
ai-unify-product-images.min.js.LICENSE.txt
324
0666
edit
dl
rm
ai-unify-product-images.strings.js
45
0666
edit
dl
rm
ai.js
1328605
0666
edit
dl
rm
ai.min.js
522494
0666
edit
dl
rm
ai.min.js.LICENSE.txt
324
0666
edit
dl
rm
ai.strings.js
21782
0666
edit
dl
rm
alert.b4336601ffdb6086d1b5.bundle.min.js
618
0666
edit
dl
rm
alert.fd509aa768e7b35a8e32.bundle.js
1405
0666
edit
dl
rm
announcements-app.js
121644
0666
edit
dl
rm
announcements-app.min.js
38416
0666
edit
dl
rm
announcements-app.min.js.LICENSE.txt
163
0666
edit
dl
rm
announcements-app.strings.js
35
0666
edit
dl
rm
app-loader.js
101270
0666
edit
dl
rm
app-loader.min.js
39069
0666
edit
dl
rm
app-loader.strings.js
39250
0666
edit
dl
rm
app-packages.js
369086
0666
edit
dl
rm
app-packages.min.js
125498
0666
edit
dl
rm
app-packages.min.js.LICENSE.txt
163
0666
edit
dl
rm
app-packages.strings.js
39250
0666
edit
dl
rm
app.js
1457122
0666
edit
dl
rm
app.min.js
535194
0666
edit
dl
rm
app.min.js.LICENSE.txt
163
0666
edit
dl
rm
app.strings.js
39250
0666
edit
dl
rm
assets-manager.js
28442
0666
edit
dl
rm
assets-manager.min.js
11980
0666
edit
dl
rm
assets-manager.min.js.LICENSE.txt
163
0666
edit
dl
rm
assets-manager.strings.js
0
0666
edit
dl
rm
atomic-widgets-action-link-handler.js
109140
0666
edit
dl
rm
atomic-widgets-action-link-handler.min.js
20388
0666
edit
dl
rm
atomic-widgets-editor.js
164160
0666
edit
dl
rm
atomic-widgets-editor.min.js
68766
0666
edit
dl
rm
atomic-widgets-editor.min.js.LICENSE.txt
163
0666
edit
dl
rm
atomic-widgets-editor.strings.js
356
0666
edit
dl
rm
atomic-widgets-form-handler.js
688888
0666
edit
dl
rm
atomic-widgets-form-handler.min.js
117479
0666
edit
dl
rm
atomic-widgets-form-handler.min.js.LICENSE.txt
336
0666
edit
dl
rm
b1e33a4cb2c6d38a6baa.bundle.min.js
1560
0666
edit
dl
rm
b4d39e5186d768f79598.bundle.js
1224
0666
edit
dl
rm
b96d70044d0d67c2df19.bundle.min.js
23415
0666
edit
dl
rm
beta-tester.js
21418
0666
edit
dl
rm
beta-tester.min.js
8822
0666
edit
dl
rm
beta-tester.strings.js
69
0666
edit
dl
rm
bf2fa9f81b3d78f5858f.bundle.min.js
669
0666
edit
dl
rm
c13d205fa26f8af1ce7c.bundle.js
114102
0666
edit
dl
rm
c73a7d15e48e3305780a.bundle.min.js
1307
0666
edit
dl
rm
cb2834c8227e56659152.bundle.min.js
1426
0666
edit
dl
rm
cf6ec600fcf4e08ba6d3.bundle.js
613
0666
edit
dl
rm
checklist.js
163183
0666
edit
dl
rm
checklist.min.js
50953
0666
edit
dl
rm
checklist.min.js.LICENSE.txt
163
0666
edit
dl
rm
checklist.strings.js
551
0666
edit
dl
rm
cloud-library-screenshot.js
88992
0666
edit
dl
rm
cloud-library-screenshot.min.js
32969
0666
edit
dl
rm
cloud-library-screenshot.min.js.LICENSE.txt
163
0666
edit
dl
rm
cloud-library-screenshot.strings.js
0
0666
edit
dl
rm
common-modules.js
152271
0666
edit
dl
rm
common-modules.min.js
58348
0666
edit
dl
rm
common-modules.strings.js
431
0666
edit
dl
rm
common.js
1204156
0666
edit
dl
rm
common.min.js
490844
0666
edit
dl
rm
common.min.js.LICENSE.txt
163
0666
edit
dl
rm
common.strings.js
431
0666
edit
dl
rm
contact-buttons.086261d3e9c4d8037686.bundle.js
14848
0666
edit
dl
rm
contact-buttons.e98d0220ce8c38404e7e.bundle.min.js
8663
0666
edit
dl
rm
container-converter.js
51971
0666
edit
dl
rm
container-converter.min.js
18280
0666
edit
dl
rm
container-converter.strings.js
208
0666
edit
dl
rm
container-editor-handlers.49d65af3a7e15d2d67e8.bundle.min.js
13232
0666
edit
dl
rm
container-editor-handlers.b45e73e31bdb50fb2cd1.bundle.js
24216
0666
edit
dl
rm
counter.7310c276bc7865a3d438.bundle.js
1893
0666
edit
dl
rm
counter.12335f45aaa79d244f24.bundle.min.js
906
0666
edit
dl
rm
d8a330693f9211e2166e.bundle.min.js
4584
0666
edit
dl
rm
d39cd4cb3d5b09b11c14.bundle.min.js
5459
0666
edit
dl
rm
d42de03ef4a0f50e39ca.bundle.min.js
176
0666
edit
dl
rm
d52aa05c75af56327744.bundle.js
14479
0666
edit
dl
rm
d67ddd6f08b08392c42f.bundle.js
15055
0666
edit
dl
rm
d69d9b30e379355f1464.bundle.min.js
1374
0666
edit
dl
rm
d84c0b1bbfe78744e722.bundle.js
1967
0666
edit
dl
rm
d224ff58c11185a05291.bundle.js
1968
0666
edit
dl
rm
daedc6797eaad5c82711.bundle.min.js
4060
0666
edit
dl
rm
de7511b88f9ec0968921.bundle.js
1116
0666
edit
dl
rm
design-system-sync.js
2347
0666
edit
dl
rm
design-system-sync.min.js
1030
0666
edit
dl
rm
design-system-sync.strings.js
0
0666
edit
dl
rm
dev-tools.js
23816
0666
edit
dl
rm
dev-tools.min.js
7577
0666
edit
dl
rm
dev-tools.strings.js
0
0666
edit
dl
rm
df4ff09f2b412abf0cd3.bundle.js
5348
0666
edit
dl
rm
dff865a4d52c12bcf996.bundle.min.js
662
0666
edit
dl
rm
e-conversion-banner.js
21529
0666
edit
dl
rm
e-conversion-banner.min.js
8569
0666
edit
dl
rm
e-conversion-banner.min.js.LICENSE.txt
163
0666
edit
dl
rm
e-conversion-banner.strings.js
0
0666
edit
dl
rm
e-home-screen.js
263249
0666
edit
dl
rm
e-home-screen.min.js
95805
0666
edit
dl
rm
e-home-screen.min.js.LICENSE.txt
163
0666
edit
dl
rm
e-home-screen.strings.js
445
0666
edit
dl
rm
e-react-promotions.js
1348334
0666
edit
dl
rm
e-react-promotions.min.js
926126
0666
edit
dl
rm
e-react-promotions.min.js.LICENSE.txt
69
0666
edit
dl
rm
e-react-promotions.strings.js
127
0666
edit
dl
rm
e-wc-product-editor.js
106990
0666
edit
dl
rm
e-wc-product-editor.min.js
17141
0666
edit
dl
rm
e-wc-product-editor.min.js.LICENSE.txt
160
0666
edit
dl
rm
e-wc-product-editor.strings.js
41
0666
edit
dl
rm
e1c444bff8c609679f7a.bundle.js
2063
0666
edit
dl
rm
e1cb4d726bb59646c677.bundle.min.js
5392
0666
edit
dl
rm
e9a764dcd37c06162942.bundle.js
1146
0666
edit
dl
rm
e459c6c89c0c0899c850.bundle.js
91999
0666
edit
dl
rm
ec1ee92b2a471389c7b9.bundle.min.js
659
0666
edit
dl
rm
editor-document.js
71576
0666
edit
dl
rm
editor-document.min.js
25841
0666
edit
dl
rm
editor-document.strings.js
19207
0666
edit
dl
rm
editor-environment-v2.js
600
0666
edit
dl
rm
editor-environment-v2.min.js
206
0666
edit
dl
rm
editor-environment-v2.strings.js
0
0666
edit
dl
rm
editor-interactions.js
44037
0666
edit
dl
rm
editor-interactions.min.js
19091
0666
edit
dl
rm
editor-interactions.strings.js
0
0666
edit
dl
rm
editor-loader-v1.js
332
0666
edit
dl
rm
editor-loader-v1.min.js
48
0666
edit
dl
rm
editor-loader-v1.strings.js
0
0666
edit
dl
rm
editor-loader-v2.js
821
0666
edit
dl
rm
editor-loader-v2.min.js
400
0666
edit
dl
rm
editor-loader-v2.strings.js
0
0666
edit
dl
rm
editor-modules.js
120959
0666
edit
dl
rm
editor-modules.min.js
49544
0666
edit
dl
rm
editor-modules.min.js.LICENSE.txt
163
0666
edit
dl
rm
editor-modules.strings.js
19207
0666
edit
dl
rm
editor-notifications.js
88637
0666
edit
dl
rm
editor-notifications.min.js
19152
0666
edit
dl
rm
editor-notifications.strings.js
100
0666
edit
dl
rm
editor-one-admin.js
635
0666
edit
dl
rm
editor-one-admin.min.js
275
0666
edit
dl
rm
editor-one-admin.strings.js
0
0666
edit
dl
rm
editor-one-menu.js
73487
0666
edit
dl
rm
editor-one-menu.min.js
32647
0666
edit
dl
rm
editor-one-menu.strings.js
0
0666
edit
dl
rm
editor-one-sidebar-navigation.js
270894
0666
edit
dl
rm
editor-one-sidebar-navigation.min.js
68054
0666
edit
dl
rm
editor-one-sidebar-navigation.min.js.LICENSE.txt
160
0666
edit
dl
rm
editor-one-sidebar-navigation.strings.js
0
0666
edit
dl
rm
editor-one-top-bar.js
1263736
0666
edit
dl
rm
editor-one-top-bar.min.js
1050260
0666
edit
dl
rm
editor-one-top-bar.min.js.LICENSE.txt
410
0666
edit
dl
rm
editor-one-top-bar.strings.js
0
0666
edit
dl
rm
editor-v4-opt-in-alphachip.js
60711
0666
edit
dl
rm
editor-v4-opt-in-alphachip.min.js
8758
0666
edit
dl
rm
editor-v4-opt-in-alphachip.strings.js
206
0666
edit
dl
rm
editor-v4-opt-in.js
170953
0666
edit
dl
rm
editor-v4-opt-in.min.js
53072
0666
edit
dl
rm
editor-v4-opt-in.min.js.LICENSE.txt
352
0666
edit
dl
rm
editor-v4-opt-in.strings.js
2426
0666
edit
dl
rm
editor.js
2962168
0666
edit
dl
rm
editor.min.js
1273077
0666
edit
dl
rm
editor.min.js.LICENSE.txt
352
0666
edit
dl
rm
editor.strings.js
1857
0666
edit
dl
rm
ef35c83e4628f0a5c328.bundle.js
636
0666
edit
dl
rm
ef2100ac3eda1a957819.bundle.min.js
5050
0666
edit
dl
rm
element-manager-admin.js
247128
0666
edit
dl
rm
element-manager-admin.min.js
61808
0666
edit
dl
rm
element-manager-admin.min.js.LICENSE.txt
324
0666
edit
dl
rm
element-manager-admin.strings.js
2098
0666
edit
dl
rm
elementor-admin-bar.js
18603
0666
edit
dl
rm
elementor-admin-bar.min.js
7313
0666
edit
dl
rm
elementor-admin-bar.strings.js
0
0666
edit
dl
rm
f3b4453f66034a6655a7.bundle.min.js
4670
0666
edit
dl
rm
fd59b90c4d338489adcc.bundle.min.js
1368
0666
edit
dl
rm
floating-bars.740d06d17cea5cebdb61.bundle.min.js
7879
0666
edit
dl
rm
floating-bars.a6e6a043444b62f64f82.bundle.js
14989
0666
edit
dl
rm
floating-elements-modal.js
35456
0666
edit
dl
rm
floating-elements-modal.min.js
15109
0666
edit
dl
rm
floating-elements-modal.strings.js
43
0666
edit
dl
rm
frontend-modules.js
193758
0666
edit
dl
rm
frontend-modules.min.js
50602
0666
edit
dl
rm
frontend.js
97435
0666
edit
dl
rm
frontend.min.js
32098
0666
edit
dl
rm
gutenberg.js
7613
0666
edit
dl
rm
gutenberg.min.js
4046
0666
edit
dl
rm
gutenberg.strings.js
1468
0666
edit
dl
rm
image-carousel.8b25f3674c29b829a867.bundle.js
905
0666
edit
dl
rm
image-carousel.6167d20b95b33386757b.bundle.min.js
408
0666
edit
dl
rm
import-export-admin.js
15304
0666
edit
dl
rm
import-export-admin.min.js
6529
0666
edit
dl
rm
import-export-admin.strings.js
12513
0666
edit
dl
rm
import-export-customization-admin.js
79524
0666
edit
dl
rm
import-export-customization-admin.min.js
38759
0666
edit
dl
rm
import-export-customization-admin.min.js.LICENSE.txt
163
0666
edit
dl
rm
import-export-customization-admin.strings.js
13421
0666
edit
dl
rm
interactions-shared-utils.js
27331
0666
edit
dl
rm
interactions-shared-utils.min.js
10744
0666
edit
dl
rm
interactions-shared-utils.strings.js
0
0666
edit
dl
rm
interactions.js
40792
0666
edit
dl
rm
interactions.min.js
17096
0666
edit
dl
rm
interactions.strings.js
0
0666
edit
dl
rm
kit-elements-defaults-editor.js
87139
0666
edit
dl
rm
kit-elements-defaults-editor.min.js
32712
0666
edit
dl
rm
kit-elements-defaults-editor.min.js.LICENSE.txt
163
0666
edit
dl
rm
kit-elements-defaults-editor.strings.js
687
0666
edit
dl
rm
kit-library.38e1af453464e7ef7a6e.bundle.min.js
177026
0666
edit
dl
rm
kit-library.816d964bf4c39d277a8e.bundle.js
373976
0666
edit
dl
rm
lightbox.3f9b3a051b2336dd5372.bundle.min.js
29496
0666
edit
dl
rm
lightbox.21984471d5ca0db94445.bundle.js
51015
0666
edit
dl
rm
media-hints.js
11942
0666
edit
dl
rm
media-hints.min.js
6122
0666
edit
dl
rm
media-hints.strings.js
0
0666
edit
dl
rm
nested-accordion.294d40984397351fd0f5.bundle.min.js
9761
0666
edit
dl
rm
nested-accordion.4340b64226322f36bcc0.bundle.js
19310
0666
edit
dl
rm
nested-accordion.js
29624
0666
edit
dl
rm
nested-accordion.min.js
10859
0666
edit
dl
rm
nested-accordion.min.js.LICENSE.txt
163
0666
edit
dl
rm
nested-accordion.strings.js
0
0666
edit
dl
rm
nested-elements.js
20660
0666
edit
dl
rm
nested-elements.min.js
6396
0666
edit
dl
rm
nested-elements.strings.js
150
0666
edit
dl
rm
nested-tabs.7a338e6d7e060c473993.bundle.js
21159
0666
edit
dl
rm
nested-tabs.a2401356d329f179475e.bundle.min.js
11354
0666
edit
dl
rm
nested-tabs.js
29584
0666
edit
dl
rm
nested-tabs.min.js
10854
0666
edit
dl
rm
nested-tabs.min.js.LICENSE.txt
163
0666
edit
dl
rm
nested-tabs.strings.js
0
0666
edit
dl
rm
nested-title-keyboard-handler.0c2b498e3e0695a1dc19.bundle.js
7918
0666
edit
dl
rm
nested-title-keyboard-handler.2a67d3cc630e11815acc.bundle.min.js
4321
0666
edit
dl
rm
new-template.js
16010
0666
edit
dl
rm
new-template.min.js
7044
0666
edit
dl
rm
new-template.strings.js
34
0666
edit
dl
rm
notes.js
24121
0666
edit
dl
rm
notes.min.js
9070
0666
edit
dl
rm
notes.strings.js
276
0666
edit
dl
rm
pro-free-trial-popup.js
59340
0666
edit
dl
rm
pro-free-trial-popup.min.js
8494
0666
edit
dl
rm
pro-free-trial-popup.strings.js
0
0666
edit
dl
rm
pro-install-events.js
3122
0666
edit
dl
rm
pro-install-events.min.js
1750
0666
edit
dl
rm
pro-install-events.strings.js
0
0666
edit
dl
rm
progress.0ea083b809812c0e3aa1.bundle.min.js
789
0666
edit
dl
rm
progress.b1057ba870016558bce1.bundle.js
1940
0666
edit
dl
rm
responsive-bar.js
25386
0666
edit
dl
rm
responsive-bar.min.js
11553
0666
edit
dl
rm
responsive-bar.strings.js
76
0666
edit
dl
rm
section-editor-handlers.53ffedef32043348b99b.bundle.min.js
1744
0666
edit
dl
rm
section-editor-handlers.d65899d232b5339510d7.bundle.js
3460
0666
edit
dl
rm
section-frontend-handlers.c3950c6b190ca134bc8d.bundle.js
1007
0666
edit
dl
rm
section-frontend-handlers.d85ab872da118940910d.bundle.min.js
449
0666
edit
dl
rm
shared-editor-handlers.3023894100138e442ab0.bundle.js
2017
0666
edit
dl
rm
shared-editor-handlers.cacdcbed391abf4b48b0.bundle.min.js
1174
0666
edit
dl
rm
shared-frontend-handlers.03caa53373b56d3bab67.bundle.min.js
8481
0666
edit
dl
rm
shared-frontend-handlers.3b079824c37a5fe2bdaa.bundle.js
16230
0666
edit
dl
rm
styleguide-app-initiator.js
37419
0666
edit
dl
rm
styleguide-app-initiator.min.js
13344
0666
edit
dl
rm
styleguide-app-initiator.min.js.LICENSE.txt
163
0666
edit
dl
rm
styleguide-app-initiator.strings.js
372
0666
edit
dl
rm
styleguide-app.04340244193733d78622.bundle.min.js
26217
0666
edit
dl
rm
styleguide-app.36ecabae74d9b87fc5a8.bundle.js
67836
0666
edit
dl
rm
styleguide.js
98960
0666
edit
dl
rm
styleguide.min.js
44931
0666
edit
dl
rm
styleguide.strings.js
372
0666
edit
dl
rm
tabs-handler.js
111171
0666
edit
dl
rm
tabs-handler.min.js
21425
0666
edit
dl
rm
tabs-preview-handler.js
109784
0666
edit
dl
rm
tabs-preview-handler.min.js
20592
0666
edit
dl
rm
tabs.18344b05d8d1ea0702bc.bundle.min.js
3701
0666
edit
dl
rm
tabs.40498fa771d612162c53.bundle.js
7854
0666
edit
dl
rm
text-editor.0c9960167105139d27c9.bundle.js
3067
0666
edit
dl
rm
text-editor.45609661e409413f1cef.bundle.min.js
1348
0666
edit
dl
rm
text-path.6db73cc0a10a70f128eb.bundle.js
8560
0666
edit
dl
rm
text-path.a67c1f3a78d208bc7e1b.bundle.min.js
3326
0666
edit
dl
rm
toggle.2a177a3ef4785d3dfbc5.bundle.min.js
3769
0666
edit
dl
rm
toggle.b75e66d2aca6f6ee742e.bundle.js
7958
0666
edit
dl
rm
vendors-redux.js
276093
0666
edit
dl
rm
vendors-redux.min.js
69128
0666
edit
dl
rm
vendors-redux.min.js.LICENSE.txt
1019
0666
edit
dl
rm
vendors-redux.strings.js
431
0666
edit
dl
rm
video.6e96510afa701d1f2ebc.bundle.js
6479
0666
edit
dl
rm
video.86d44e46e43d0807e708.bundle.min.js
3223
0666
edit
dl
rm
web-cli.js
336046
0666
edit
dl
rm
web-cli.min.js
119227
0666
edit
dl
rm
web-cli.min.js.LICENSE.txt
163
0666
edit
dl
rm
web-cli.strings.js
0
0666
edit
dl
rm
webpack.runtime.js
17065
0666
edit
dl
rm
webpack.runtime.min.js
5819
0666
edit
dl
rm
wp-audio.0ba9114964acf4c37ca2.bundle.js
757
0666
edit
dl
rm
wp-audio.c9624cb6e5dc9de86abd.bundle.min.js
326
0666
edit
dl
rm
youtube-handler.js
4802
0666
edit
dl
rm
youtube-handler.min.js
1859
0666
edit
dl
rm
Edit:
/home/techb158/public_html/wp-content/plugins/elementor/assets/js/6caa76d2f6eec6c4e665.bundle.js
(64411B)
"use strict"; (self["webpackChunkelementorFrontend"] = self["webpackChunkelementorFrontend"] || []).push([["vendors-node_modules_dompurify_dist_purify_cjs_js"],{ /***/ "../node_modules/dompurify/dist/purify.cjs.js": /*!****************************************************!*\ !*** ../node_modules/dompurify/dist/purify.cjs.js ***! \****************************************************/ /***/ ((module) => { /*! @license DOMPurify 3.3.0 | (c) Cure53 and other contributors | Released under the Apache license 2.0 and Mozilla Public License 2.0 | github.com/cure53/DOMPurify/blob/3.3.0/LICENSE */ const { entries, setPrototypeOf, isFrozen, getPrototypeOf, getOwnPropertyDescriptor } = Object; let { freeze, seal, create } = Object; // eslint-disable-line import/no-mutable-exports let { apply, construct } = typeof Reflect !== 'undefined' && Reflect; if (!freeze) { freeze = function freeze(x) { return x; }; } if (!seal) { seal = function seal(x) { return x; }; } if (!apply) { apply = function apply(func, thisArg) { for (var _len = arguments.length, args = new Array(_len > 2 ? _len - 2 : 0), _key = 2; _key < _len; _key++) { args[_key - 2] = arguments[_key]; } return func.apply(thisArg, args); }; } if (!construct) { construct = function construct(Func) { for (var _len2 = arguments.length, args = new Array(_len2 > 1 ? _len2 - 1 : 0), _key2 = 1; _key2 < _len2; _key2++) { args[_key2 - 1] = arguments[_key2]; } return new Func(...args); }; } const arrayForEach = unapply(Array.prototype.forEach); const arrayLastIndexOf = unapply(Array.prototype.lastIndexOf); const arrayPop = unapply(Array.prototype.pop); const arrayPush = unapply(Array.prototype.push); const arraySplice = unapply(Array.prototype.splice); const stringToLowerCase = unapply(String.prototype.toLowerCase); const stringToString = unapply(String.prototype.toString); const stringMatch = unapply(String.prototype.match); const stringReplace = unapply(String.prototype.replace); const stringIndexOf = unapply(String.prototype.indexOf); const stringTrim = unapply(String.prototype.trim); const objectHasOwnProperty = unapply(Object.prototype.hasOwnProperty); const regExpTest = unapply(RegExp.prototype.test); const typeErrorCreate = unconstruct(TypeError); /** * Creates a new function that calls the given function with a specified thisArg and arguments. * * @param func - The function to be wrapped and called. * @returns A new function that calls the given function with a specified thisArg and arguments. */ function unapply(func) { return function (thisArg) { if (thisArg instanceof RegExp) { thisArg.lastIndex = 0; } for (var _len3 = arguments.length, args = new Array(_len3 > 1 ? _len3 - 1 : 0), _key3 = 1; _key3 < _len3; _key3++) { args[_key3 - 1] = arguments[_key3]; } return apply(func, thisArg, args); }; } /** * Creates a new function that constructs an instance of the given constructor function with the provided arguments. * * @param func - The constructor function to be wrapped and called. * @returns A new function that constructs an instance of the given constructor function with the provided arguments. */ function unconstruct(Func) { return function () { for (var _len4 = arguments.length, args = new Array(_len4), _key4 = 0; _key4 < _len4; _key4++) { args[_key4] = arguments[_key4]; } return construct(Func, args); }; } /** * Add properties to a lookup table * * @param set - The set to which elements will be added. * @param array - The array containing elements to be added to the set. * @param transformCaseFunc - An optional function to transform the case of each element before adding to the set. * @returns The modified set with added elements. */ function addToSet(set, array) { let transformCaseFunc = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : stringToLowerCase; if (setPrototypeOf) { // Make 'in' and truthy checks like Boolean(set.constructor) // independent of any properties defined on Object.prototype. // Prevent prototype setters from intercepting set as a this value. setPrototypeOf(set, null); } let l = array.length; while (l--) { let element = array[l]; if (typeof element === 'string') { const lcElement = transformCaseFunc(element); if (lcElement !== element) { // Config presets (e.g. tags.js, attrs.js) are immutable. if (!isFrozen(array)) { array[l] = lcElement; } element = lcElement; } } set[element] = true; } return set; } /** * Clean up an array to harden against CSPP * * @param array - The array to be cleaned. * @returns The cleaned version of the array */ function cleanArray(array) { for (let index = 0; index < array.length; index++) { const isPropertyExist = objectHasOwnProperty(array, index); if (!isPropertyExist) { array[index] = null; } } return array; } /** * Shallow clone an object * * @param object - The object to be cloned. * @returns A new object that copies the original. */ function clone(object) { const newObject = create(null); for (const [property, value] of entries(object)) { const isPropertyExist = objectHasOwnProperty(object, property); if (isPropertyExist) { if (Array.isArray(value)) { newObject[property] = cleanArray(value); } else if (value && typeof value === 'object' && value.constructor === Object) { newObject[property] = clone(value); } else { newObject[property] = value; } } } return newObject; } /** * This method automatically checks if the prop is function or getter and behaves accordingly. * * @param object - The object to look up the getter function in its prototype chain. * @param prop - The property name for which to find the getter function. * @returns The getter function found in the prototype chain or a fallback function. */ function lookupGetter(object, prop) { while (object !== null) { const desc = getOwnPropertyDescriptor(object, prop); if (desc) { if (desc.get) { return unapply(desc.get); } if (typeof desc.value === 'function') { return unapply(desc.value); } } object = getPrototypeOf(object); } function fallbackValue() { return null; } return fallbackValue; } const html$1 = freeze(['a', 'abbr', 'acronym', 'address', 'area', 'article', 'aside', 'audio', 'b', 'bdi', 'bdo', 'big', 'blink', 'blockquote', 'body', 'br', 'button', 'canvas', 'caption', 'center', 'cite', 'code', 'col', 'colgroup', 'content', 'data', 'datalist', 'dd', 'decorator', 'del', 'details', 'dfn', 'dialog', 'dir', 'div', 'dl', 'dt', 'element', 'em', 'fieldset', 'figcaption', 'figure', 'font', 'footer', 'form', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'head', 'header', 'hgroup', 'hr', 'html', 'i', 'img', 'input', 'ins', 'kbd', 'label', 'legend', 'li', 'main', 'map', 'mark', 'marquee', 'menu', 'menuitem', 'meter', 'nav', 'nobr', 'ol', 'optgroup', 'option', 'output', 'p', 'picture', 'pre', 'progress', 'q', 'rp', 'rt', 'ruby', 's', 'samp', 'search', 'section', 'select', 'shadow', 'slot', 'small', 'source', 'spacer', 'span', 'strike', 'strong', 'style', 'sub', 'summary', 'sup', 'table', 'tbody', 'td', 'template', 'textarea', 'tfoot', 'th', 'thead', 'time', 'tr', 'track', 'tt', 'u', 'ul', 'var', 'video', 'wbr']); const svg$1 = freeze(['svg', 'a', 'altglyph', 'altglyphdef', 'altglyphitem', 'animatecolor', 'animatemotion', 'animatetransform', 'circle', 'clippath', 'defs', 'desc', 'ellipse', 'enterkeyhint', 'exportparts', 'filter', 'font', 'g', 'glyph', 'glyphref', 'hkern', 'image', 'inputmode', 'line', 'lineargradient', 'marker', 'mask', 'metadata', 'mpath', 'part', 'path', 'pattern', 'polygon', 'polyline', 'radialgradient', 'rect', 'stop', 'style', 'switch', 'symbol', 'text', 'textpath', 'title', 'tref', 'tspan', 'view', 'vkern']); const svgFilters = freeze(['feBlend', 'feColorMatrix', 'feComponentTransfer', 'feComposite', 'feConvolveMatrix', 'feDiffuseLighting', 'feDisplacementMap', 'feDistantLight', 'feDropShadow', 'feFlood', 'feFuncA', 'feFuncB', 'feFuncG', 'feFuncR', 'feGaussianBlur', 'feImage', 'feMerge', 'feMergeNode', 'feMorphology', 'feOffset', 'fePointLight', 'feSpecularLighting', 'feSpotLight', 'feTile', 'feTurbulence']); // List of SVG elements that are disallowed by default. // We still need to know them so that we can do namespace // checks properly in case one wants to add them to // allow-list. const svgDisallowed = freeze(['animate', 'color-profile', 'cursor', 'discard', 'font-face', 'font-face-format', 'font-face-name', 'font-face-src', 'font-face-uri', 'foreignobject', 'hatch', 'hatchpath', 'mesh', 'meshgradient', 'meshpatch', 'meshrow', 'missing-glyph', 'script', 'set', 'solidcolor', 'unknown', 'use']); const mathMl$1 = freeze(['math', 'menclose', 'merror', 'mfenced', 'mfrac', 'mglyph', 'mi', 'mlabeledtr', 'mmultiscripts', 'mn', 'mo', 'mover', 'mpadded', 'mphantom', 'mroot', 'mrow', 'ms', 'mspace', 'msqrt', 'mstyle', 'msub', 'msup', 'msubsup', 'mtable', 'mtd', 'mtext', 'mtr', 'munder', 'munderover', 'mprescripts']); // Similarly to SVG, we want to know all MathML elements, // even those that we disallow by default. const mathMlDisallowed = freeze(['maction', 'maligngroup', 'malignmark', 'mlongdiv', 'mscarries', 'mscarry', 'msgroup', 'mstack', 'msline', 'msrow', 'semantics', 'annotation', 'annotation-xml', 'mprescripts', 'none']); const text = freeze(['#text']); const html = freeze(['accept', 'action', 'align', 'alt', 'autocapitalize', 'autocomplete', 'autopictureinpicture', 'autoplay', 'background', 'bgcolor', 'border', 'capture', 'cellpadding', 'cellspacing', 'checked', 'cite', 'class', 'clear', 'color', 'cols', 'colspan', 'controls', 'controlslist', 'coords', 'crossorigin', 'datetime', 'decoding', 'default', 'dir', 'disabled', 'disablepictureinpicture', 'disableremoteplayback', 'download', 'draggable', 'enctype', 'enterkeyhint', 'exportparts', 'face', 'for', 'headers', 'height', 'hidden', 'high', 'href', 'hreflang', 'id', 'inert', 'inputmode', 'integrity', 'ismap', 'kind', 'label', 'lang', 'list', 'loading', 'loop', 'low', 'max', 'maxlength', 'media', 'method', 'min', 'minlength', 'multiple', 'muted', 'name', 'nonce', 'noshade', 'novalidate', 'nowrap', 'open', 'optimum', 'part', 'pattern', 'placeholder', 'playsinline', 'popover', 'popovertarget', 'popovertargetaction', 'poster', 'preload', 'pubdate', 'radiogroup', 'readonly', 'rel', 'required', 'rev', 'reversed', 'role', 'rows', 'rowspan', 'spellcheck', 'scope', 'selected', 'shape', 'size', 'sizes', 'slot', 'span', 'srclang', 'start', 'src', 'srcset', 'step', 'style', 'summary', 'tabindex', 'title', 'translate', 'type', 'usemap', 'valign', 'value', 'width', 'wrap', 'xmlns', 'slot']); const svg = freeze(['accent-height', 'accumulate', 'additive', 'alignment-baseline', 'amplitude', 'ascent', 'attributename', 'attributetype', 'azimuth', 'basefrequency', 'baseline-shift', 'begin', 'bias', 'by', 'class', 'clip', 'clippathunits', 'clip-path', 'clip-rule', 'color', 'color-interpolation', 'color-interpolation-filters', 'color-profile', 'color-rendering', 'cx', 'cy', 'd', 'dx', 'dy', 'diffuseconstant', 'direction', 'display', 'divisor', 'dur', 'edgemode', 'elevation', 'end', 'exponent', 'fill', 'fill-opacity', 'fill-rule', 'filter', 'filterunits', 'flood-color', 'flood-opacity', 'font-family', 'font-size', 'font-size-adjust', 'font-stretch', 'font-style', 'font-variant', 'font-weight', 'fx', 'fy', 'g1', 'g2', 'glyph-name', 'glyphref', 'gradientunits', 'gradienttransform', 'height', 'href', 'id', 'image-rendering', 'in', 'in2', 'intercept', 'k', 'k1', 'k2', 'k3', 'k4', 'kerning', 'keypoints', 'keysplines', 'keytimes', 'lang', 'lengthadjust', 'letter-spacing', 'kernelmatrix', 'kernelunitlength', 'lighting-color', 'local', 'marker-end', 'marker-mid', 'marker-start', 'markerheight', 'markerunits', 'markerwidth', 'maskcontentunits', 'maskunits', 'max', 'mask', 'mask-type', 'media', 'method', 'mode', 'min', 'name', 'numoctaves', 'offset', 'operator', 'opacity', 'order', 'orient', 'orientation', 'origin', 'overflow', 'paint-order', 'path', 'pathlength', 'patterncontentunits', 'patterntransform', 'patternunits', 'points', 'preservealpha', 'preserveaspectratio', 'primitiveunits', 'r', 'rx', 'ry', 'radius', 'refx', 'refy', 'repeatcount', 'repeatdur', 'restart', 'result', 'rotate', 'scale', 'seed', 'shape-rendering', 'slope', 'specularconstant', 'specularexponent', 'spreadmethod', 'startoffset', 'stddeviation', 'stitchtiles', 'stop-color', 'stop-opacity', 'stroke-dasharray', 'stroke-dashoffset', 'stroke-linecap', 'stroke-linejoin', 'stroke-miterlimit', 'stroke-opacity', 'stroke', 'stroke-width', 'style', 'surfacescale', 'systemlanguage', 'tabindex', 'tablevalues', 'targetx', 'targety', 'transform', 'transform-origin', 'text-anchor', 'text-decoration', 'text-rendering', 'textlength', 'type', 'u1', 'u2', 'unicode', 'values', 'viewbox', 'visibility', 'version', 'vert-adv-y', 'vert-origin-x', 'vert-origin-y', 'width', 'word-spacing', 'wrap', 'writing-mode', 'xchannelselector', 'ychannelselector', 'x', 'x1', 'x2', 'xmlns', 'y', 'y1', 'y2', 'z', 'zoomandpan']); const mathMl = freeze(['accent', 'accentunder', 'align', 'bevelled', 'close', 'columnsalign', 'columnlines', 'columnspan', 'denomalign', 'depth', 'dir', 'display', 'displaystyle', 'encoding', 'fence', 'frame', 'height', 'href', 'id', 'largeop', 'length', 'linethickness', 'lspace', 'lquote', 'mathbackground', 'mathcolor', 'mathsize', 'mathvariant', 'maxsize', 'minsize', 'movablelimits', 'notation', 'numalign', 'open', 'rowalign', 'rowlines', 'rowspacing', 'rowspan', 'rspace', 'rquote', 'scriptlevel', 'scriptminsize', 'scriptsizemultiplier', 'selection', 'separator', 'separators', 'stretchy', 'subscriptshift', 'supscriptshift', 'symmetric', 'voffset', 'width', 'xmlns']); const xml = freeze(['xlink:href', 'xml:id', 'xlink:title', 'xml:space', 'xmlns:xlink']); // eslint-disable-next-line unicorn/better-regex const MUSTACHE_EXPR = seal(/\{\{[\w\W]*|[\w\W]*\}\}/gm); // Specify template detection regex for SAFE_FOR_TEMPLATES mode const ERB_EXPR = seal(/<%[\w\W]*|[\w\W]*%>/gm); const TMPLIT_EXPR = seal(/\$\{[\w\W]*/gm); // eslint-disable-line unicorn/better-regex const DATA_ATTR = seal(/^data-[\-\w.\u00B7-\uFFFF]+$/); // eslint-disable-line no-useless-escape const ARIA_ATTR = seal(/^aria-[\-\w]+$/); // eslint-disable-line no-useless-escape const IS_ALLOWED_URI = seal(/^(?:(?:(?:f|ht)tps?|mailto|tel|callto|sms|cid|xmpp|matrix):|[^a-z]|[a-z+.\-]+(?:[^a-z+.\-:]|$))/i // eslint-disable-line no-useless-escape ); const IS_SCRIPT_OR_DATA = seal(/^(?:\w+script|data):/i); const ATTR_WHITESPACE = seal(/[\u0000-\u0020\u00A0\u1680\u180E\u2000-\u2029\u205F\u3000]/g // eslint-disable-line no-control-regex ); const DOCTYPE_NAME = seal(/^html$/i); const CUSTOM_ELEMENT = seal(/^[a-z][.\w]*(-[.\w]+)+$/i); var EXPRESSIONS = /*#__PURE__*/Object.freeze({ __proto__: null, ARIA_ATTR: ARIA_ATTR, ATTR_WHITESPACE: ATTR_WHITESPACE, CUSTOM_ELEMENT: CUSTOM_ELEMENT, DATA_ATTR: DATA_ATTR, DOCTYPE_NAME: DOCTYPE_NAME, ERB_EXPR: ERB_EXPR, IS_ALLOWED_URI: IS_ALLOWED_URI, IS_SCRIPT_OR_DATA: IS_SCRIPT_OR_DATA, MUSTACHE_EXPR: MUSTACHE_EXPR, TMPLIT_EXPR: TMPLIT_EXPR }); /* eslint-disable @typescript-eslint/indent */ // https://developer.mozilla.org/en-US/docs/Web/API/Node/nodeType const NODE_TYPE = { element: 1, attribute: 2, text: 3, cdataSection: 4, entityReference: 5, // Deprecated entityNode: 6, // Deprecated progressingInstruction: 7, comment: 8, document: 9, documentType: 10, documentFragment: 11, notation: 12 // Deprecated }; const getGlobal = function getGlobal() { return typeof window === 'undefined' ? null : window; }; /** * Creates a no-op policy for internal use only. * Don't export this function outside this module! * @param trustedTypes The policy factory. * @param purifyHostElement The Script element used to load DOMPurify (to determine policy name suffix). * @return The policy created (or null, if Trusted Types * are not supported or creating the policy failed). */ const _createTrustedTypesPolicy = function _createTrustedTypesPolicy(trustedTypes, purifyHostElement) { if (typeof trustedTypes !== 'object' || typeof trustedTypes.createPolicy !== 'function') { return null; } // Allow the callers to control the unique policy name // by adding a data-tt-policy-suffix to the script element with the DOMPurify. // Policy creation with duplicate names throws in Trusted Types. let suffix = null; const ATTR_NAME = 'data-tt-policy-suffix'; if (purifyHostElement && purifyHostElement.hasAttribute(ATTR_NAME)) { suffix = purifyHostElement.getAttribute(ATTR_NAME); } const policyName = 'dompurify' + (suffix ? '#' + suffix : ''); try { return trustedTypes.createPolicy(policyName, { createHTML(html) { return html; }, createScriptURL(scriptUrl) { return scriptUrl; } }); } catch (_) { // Policy creation failed (most likely another DOMPurify script has // already run). Skip creating the policy, as this will only cause errors // if TT are enforced. console.warn('TrustedTypes policy ' + policyName + ' could not be created.'); return null; } }; const _createHooksMap = function _createHooksMap() { return { afterSanitizeAttributes: [], afterSanitizeElements: [], afterSanitizeShadowDOM: [], beforeSanitizeAttributes: [], beforeSanitizeElements: [], beforeSanitizeShadowDOM: [], uponSanitizeAttribute: [], uponSanitizeElement: [], uponSanitizeShadowNode: [] }; }; function createDOMPurify() { let window = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : getGlobal(); const DOMPurify = root => createDOMPurify(root); DOMPurify.version = '3.3.0'; DOMPurify.removed = []; if (!window || !window.document || window.document.nodeType !== NODE_TYPE.document || !window.Element) { // Not running in a browser, provide a factory function // so that you can pass your own Window DOMPurify.isSupported = false; return DOMPurify; } let { document } = window; const originalDocument = document; const currentScript = originalDocument.currentScript; const { DocumentFragment, HTMLTemplateElement, Node, Element, NodeFilter, NamedNodeMap = window.NamedNodeMap || window.MozNamedAttrMap, HTMLFormElement, DOMParser, trustedTypes } = window; const ElementPrototype = Element.prototype; const cloneNode = lookupGetter(ElementPrototype, 'cloneNode'); const remove = lookupGetter(ElementPrototype, 'remove'); const getNextSibling = lookupGetter(ElementPrototype, 'nextSibling'); const getChildNodes = lookupGetter(ElementPrototype, 'childNodes'); const getParentNode = lookupGetter(ElementPrototype, 'parentNode'); // As per issue #47, the web-components registry is inherited by a // new document created via createHTMLDocument. As per the spec // (http://w3c.github.io/webcomponents/spec/custom/#creating-and-passing-registries) // a new empty registry is used when creating a template contents owner // document, so we use that as our parent document to ensure nothing // is inherited. if (typeof HTMLTemplateElement === 'function') { const template = document.createElement('template'); if (template.content && template.content.ownerDocument) { document = template.content.ownerDocument; } } let trustedTypesPolicy; let emptyHTML = ''; const { implementation, createNodeIterator, createDocumentFragment, getElementsByTagName } = document; const { importNode } = originalDocument; let hooks = _createHooksMap(); /** * Expose whether this browser supports running the full DOMPurify. */ DOMPurify.isSupported = typeof entries === 'function' && typeof getParentNode === 'function' && implementation && implementation.createHTMLDocument !== undefined; const { MUSTACHE_EXPR, ERB_EXPR, TMPLIT_EXPR, DATA_ATTR, ARIA_ATTR, IS_SCRIPT_OR_DATA, ATTR_WHITESPACE, CUSTOM_ELEMENT } = EXPRESSIONS; let { IS_ALLOWED_URI: IS_ALLOWED_URI$1 } = EXPRESSIONS; /** * We consider the elements and attributes below to be safe. Ideally * don't add any new ones but feel free to remove unwanted ones. */ /* allowed element names */ let ALLOWED_TAGS = null; const DEFAULT_ALLOWED_TAGS = addToSet({}, [...html$1, ...svg$1, ...svgFilters, ...mathMl$1, ...text]); /* Allowed attribute names */ let ALLOWED_ATTR = null; const DEFAULT_ALLOWED_ATTR = addToSet({}, [...html, ...svg, ...mathMl, ...xml]); /* * Configure how DOMPurify should handle custom elements and their attributes as well as customized built-in elements. * @property {RegExp|Function|null} tagNameCheck one of [null, regexPattern, predicate]. Default: `null` (disallow any custom elements) * @property {RegExp|Function|null} attributeNameCheck one of [null, regexPattern, predicate]. Default: `null` (disallow any attributes not on the allow list) * @property {boolean} allowCustomizedBuiltInElements allow custom elements derived from built-ins if they pass CUSTOM_ELEMENT_HANDLING.tagNameCheck. Default: `false`. */ let CUSTOM_ELEMENT_HANDLING = Object.seal(create(null, { tagNameCheck: { writable: true, configurable: false, enumerable: true, value: null }, attributeNameCheck: { writable: true, configurable: false, enumerable: true, value: null }, allowCustomizedBuiltInElements: { writable: true, configurable: false, enumerable: true, value: false } })); /* Explicitly forbidden tags (overrides ALLOWED_TAGS/ADD_TAGS) */ let FORBID_TAGS = null; /* Explicitly forbidden attributes (overrides ALLOWED_ATTR/ADD_ATTR) */ let FORBID_ATTR = null; /* Config object to store ADD_TAGS/ADD_ATTR functions (when used as functions) */ const EXTRA_ELEMENT_HANDLING = Object.seal(create(null, { tagCheck: { writable: true, configurable: false, enumerable: true, value: null }, attributeCheck: { writable: true, configurable: false, enumerable: true, value: null } })); /* Decide if ARIA attributes are okay */ let ALLOW_ARIA_ATTR = true; /* Decide if custom data attributes are okay */ let ALLOW_DATA_ATTR = true; /* Decide if unknown protocols are okay */ let ALLOW_UNKNOWN_PROTOCOLS = false; /* Decide if self-closing tags in attributes are allowed. * Usually removed due to a mXSS issue in jQuery 3.0 */ let ALLOW_SELF_CLOSE_IN_ATTR = true; /* Output should be safe for common template engines. * This means, DOMPurify removes data attributes, mustaches and ERB */ let SAFE_FOR_TEMPLATES = false; /* Output should be safe even for XML used within HTML and alike. * This means, DOMPurify removes comments when containing risky content. */ let SAFE_FOR_XML = true; /* Decide if document with <html>... should be returned */ let WHOLE_DOCUMENT = false; /* Track whether config is already set on this instance of DOMPurify. */ let SET_CONFIG = false; /* Decide if all elements (e.g. style, script) must be children of * document.body. By default, browsers might move them to document.head */ let FORCE_BODY = false; /* Decide if a DOM `HTMLBodyElement` should be returned, instead of a html * string (or a TrustedHTML object if Trusted Types are supported). * If `WHOLE_DOCUMENT` is enabled a `HTMLHtmlElement` will be returned instead */ let RETURN_DOM = false; /* Decide if a DOM `DocumentFragment` should be returned, instead of a html * string (or a TrustedHTML object if Trusted Types are supported) */ let RETURN_DOM_FRAGMENT = false; /* Try to return a Trusted Type object instead of a string, return a string in * case Trusted Types are not supported */ let RETURN_TRUSTED_TYPE = false; /* Output should be free from DOM clobbering attacks? * This sanitizes markups named with colliding, clobberable built-in DOM APIs. */ let SANITIZE_DOM = true; /* Achieve full DOM Clobbering protection by isolating the namespace of named * properties and JS variables, mitigating attacks that abuse the HTML/DOM spec rules. * * HTML/DOM spec rules that enable DOM Clobbering: * - Named Access on Window (§7.3.3) * - DOM Tree Accessors (§3.1.5) * - Form Element Parent-Child Relations (§4.10.3) * - Iframe srcdoc / Nested WindowProxies (§4.8.5) * - HTMLCollection (§4.2.10.2) * * Namespace isolation is implemented by prefixing `id` and `name` attributes * with a constant string, i.e., `user-content-` */ let SANITIZE_NAMED_PROPS = false; const SANITIZE_NAMED_PROPS_PREFIX = 'user-content-'; /* Keep element content when removing element? */ let KEEP_CONTENT = true; /* If a `Node` is passed to sanitize(), then performs sanitization in-place instead * of importing it into a new Document and returning a sanitized copy */ let IN_PLACE = false; /* Allow usage of profiles like html, svg and mathMl */ let USE_PROFILES = {}; /* Tags to ignore content of when KEEP_CONTENT is true */ let FORBID_CONTENTS = null; const DEFAULT_FORBID_CONTENTS = addToSet({}, ['annotation-xml', 'audio', 'colgroup', 'desc', 'foreignobject', 'head', 'iframe', 'math', 'mi', 'mn', 'mo', 'ms', 'mtext', 'noembed', 'noframes', 'noscript', 'plaintext', 'script', 'style', 'svg', 'template', 'thead', 'title', 'video', 'xmp']); /* Tags that are safe for data: URIs */ let DATA_URI_TAGS = null; const DEFAULT_DATA_URI_TAGS = addToSet({}, ['audio', 'video', 'img', 'source', 'image', 'track']); /* Attributes safe for values like "javascript:" */ let URI_SAFE_ATTRIBUTES = null; const DEFAULT_URI_SAFE_ATTRIBUTES = addToSet({}, ['alt', 'class', 'for', 'id', 'label', 'name', 'pattern', 'placeholder', 'role', 'summary', 'title', 'value', 'style', 'xmlns']); const MATHML_NAMESPACE = 'http://www.w3.org/1998/Math/MathML'; const SVG_NAMESPACE = 'http://www.w3.org/2000/svg'; const HTML_NAMESPACE = 'http://www.w3.org/1999/xhtml'; /* Document namespace */ let NAMESPACE = HTML_NAMESPACE; let IS_EMPTY_INPUT = false; /* Allowed XHTML+XML namespaces */ let ALLOWED_NAMESPACES = null; const DEFAULT_ALLOWED_NAMESPACES = addToSet({}, [MATHML_NAMESPACE, SVG_NAMESPACE, HTML_NAMESPACE], stringToString); let MATHML_TEXT_INTEGRATION_POINTS = addToSet({}, ['mi', 'mo', 'mn', 'ms', 'mtext']); let HTML_INTEGRATION_POINTS = addToSet({}, ['annotation-xml']); // Certain elements are allowed in both SVG and HTML // namespace. We need to specify them explicitly // so that they don't get erroneously deleted from // HTML namespace. const COMMON_SVG_AND_HTML_ELEMENTS = addToSet({}, ['title', 'style', 'font', 'a', 'script']); /* Parsing of strict XHTML documents */ let PARSER_MEDIA_TYPE = null; const SUPPORTED_PARSER_MEDIA_TYPES = ['application/xhtml+xml', 'text/html']; const DEFAULT_PARSER_MEDIA_TYPE = 'text/html'; let transformCaseFunc = null; /* Keep a reference to config to pass to hooks */ let CONFIG = null; /* Ideally, do not touch anything below this line */ /* ______________________________________________ */ const formElement = document.createElement('form'); const isRegexOrFunction = function isRegexOrFunction(testValue) { return testValue instanceof RegExp || testValue instanceof Function; }; /** * _parseConfig * * @param cfg optional config literal */ // eslint-disable-next-line complexity const _parseConfig = function _parseConfig() { let cfg = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {}; if (CONFIG && CONFIG === cfg) { return; } /* Shield configuration object from tampering */ if (!cfg || typeof cfg !== 'object') { cfg = {}; } /* Shield configuration object from prototype pollution */ cfg = clone(cfg); PARSER_MEDIA_TYPE = // eslint-disable-next-line unicorn/prefer-includes SUPPORTED_PARSER_MEDIA_TYPES.indexOf(cfg.PARSER_MEDIA_TYPE) === -1 ? DEFAULT_PARSER_MEDIA_TYPE : cfg.PARSER_MEDIA_TYPE; // HTML tags and attributes are not case-sensitive, converting to lowercase. Keeping XHTML as is. transformCaseFunc = PARSER_MEDIA_TYPE === 'application/xhtml+xml' ? stringToString : stringToLowerCase; /* Set configuration parameters */ ALLOWED_TAGS = objectHasOwnProperty(cfg, 'ALLOWED_TAGS') ? addToSet({}, cfg.ALLOWED_TAGS, transformCaseFunc) : DEFAULT_ALLOWED_TAGS; ALLOWED_ATTR = objectHasOwnProperty(cfg, 'ALLOWED_ATTR') ? addToSet({}, cfg.ALLOWED_ATTR, transformCaseFunc) : DEFAULT_ALLOWED_ATTR; ALLOWED_NAMESPACES = objectHasOwnProperty(cfg, 'ALLOWED_NAMESPACES') ? addToSet({}, cfg.ALLOWED_NAMESPACES, stringToString) : DEFAULT_ALLOWED_NAMESPACES; URI_SAFE_ATTRIBUTES = objectHasOwnProperty(cfg, 'ADD_URI_SAFE_ATTR') ? addToSet(clone(DEFAULT_URI_SAFE_ATTRIBUTES), cfg.ADD_URI_SAFE_ATTR, transformCaseFunc) : DEFAULT_URI_SAFE_ATTRIBUTES; DATA_URI_TAGS = objectHasOwnProperty(cfg, 'ADD_DATA_URI_TAGS') ? addToSet(clone(DEFAULT_DATA_URI_TAGS), cfg.ADD_DATA_URI_TAGS, transformCaseFunc) : DEFAULT_DATA_URI_TAGS; FORBID_CONTENTS = objectHasOwnProperty(cfg, 'FORBID_CONTENTS') ? addToSet({}, cfg.FORBID_CONTENTS, transformCaseFunc) : DEFAULT_FORBID_CONTENTS; FORBID_TAGS = objectHasOwnProperty(cfg, 'FORBID_TAGS') ? addToSet({}, cfg.FORBID_TAGS, transformCaseFunc) : clone({}); FORBID_ATTR = objectHasOwnProperty(cfg, 'FORBID_ATTR') ? addToSet({}, cfg.FORBID_ATTR, transformCaseFunc) : clone({}); USE_PROFILES = objectHasOwnProperty(cfg, 'USE_PROFILES') ? cfg.USE_PROFILES : false; ALLOW_ARIA_ATTR = cfg.ALLOW_ARIA_ATTR !== false; // Default true ALLOW_DATA_ATTR = cfg.ALLOW_DATA_ATTR !== false; // Default true ALLOW_UNKNOWN_PROTOCOLS = cfg.ALLOW_UNKNOWN_PROTOCOLS || false; // Default false ALLOW_SELF_CLOSE_IN_ATTR = cfg.ALLOW_SELF_CLOSE_IN_ATTR !== false; // Default true SAFE_FOR_TEMPLATES = cfg.SAFE_FOR_TEMPLATES || false; // Default false SAFE_FOR_XML = cfg.SAFE_FOR_XML !== false; // Default true WHOLE_DOCUMENT = cfg.WHOLE_DOCUMENT || false; // Default false RETURN_DOM = cfg.RETURN_DOM || false; // Default false RETURN_DOM_FRAGMENT = cfg.RETURN_DOM_FRAGMENT || false; // Default false RETURN_TRUSTED_TYPE = cfg.RETURN_TRUSTED_TYPE || false; // Default false FORCE_BODY = cfg.FORCE_BODY || false; // Default false SANITIZE_DOM = cfg.SANITIZE_DOM !== false; // Default true SANITIZE_NAMED_PROPS = cfg.SANITIZE_NAMED_PROPS || false; // Default false KEEP_CONTENT = cfg.KEEP_CONTENT !== false; // Default true IN_PLACE = cfg.IN_PLACE || false; // Default false IS_ALLOWED_URI$1 = cfg.ALLOWED_URI_REGEXP || IS_ALLOWED_URI; NAMESPACE = cfg.NAMESPACE || HTML_NAMESPACE; MATHML_TEXT_INTEGRATION_POINTS = cfg.MATHML_TEXT_INTEGRATION_POINTS || MATHML_TEXT_INTEGRATION_POINTS; HTML_INTEGRATION_POINTS = cfg.HTML_INTEGRATION_POINTS || HTML_INTEGRATION_POINTS; CUSTOM_ELEMENT_HANDLING = cfg.CUSTOM_ELEMENT_HANDLING || {}; if (cfg.CUSTOM_ELEMENT_HANDLING && isRegexOrFunction(cfg.CUSTOM_ELEMENT_HANDLING.tagNameCheck)) { CUSTOM_ELEMENT_HANDLING.tagNameCheck = cfg.CUSTOM_ELEMENT_HANDLING.tagNameCheck; } if (cfg.CUSTOM_ELEMENT_HANDLING && isRegexOrFunction(cfg.CUSTOM_ELEMENT_HANDLING.attributeNameCheck)) { CUSTOM_ELEMENT_HANDLING.attributeNameCheck = cfg.CUSTOM_ELEMENT_HANDLING.attributeNameCheck; } if (cfg.CUSTOM_ELEMENT_HANDLING && typeof cfg.CUSTOM_ELEMENT_HANDLING.allowCustomizedBuiltInElements === 'boolean') { CUSTOM_ELEMENT_HANDLING.allowCustomizedBuiltInElements = cfg.CUSTOM_ELEMENT_HANDLING.allowCustomizedBuiltInElements; } if (SAFE_FOR_TEMPLATES) { ALLOW_DATA_ATTR = false; } if (RETURN_DOM_FRAGMENT) { RETURN_DOM = true; } /* Parse profile info */ if (USE_PROFILES) { ALLOWED_TAGS = addToSet({}, text); ALLOWED_ATTR = []; if (USE_PROFILES.html === true) { addToSet(ALLOWED_TAGS, html$1); addToSet(ALLOWED_ATTR, html); } if (USE_PROFILES.svg === true) { addToSet(ALLOWED_TAGS, svg$1); addToSet(ALLOWED_ATTR, svg); addToSet(ALLOWED_ATTR, xml); } if (USE_PROFILES.svgFilters === true) { addToSet(ALLOWED_TAGS, svgFilters); addToSet(ALLOWED_ATTR, svg); addToSet(ALLOWED_ATTR, xml); } if (USE_PROFILES.mathMl === true) { addToSet(ALLOWED_TAGS, mathMl$1); addToSet(ALLOWED_ATTR, mathMl); addToSet(ALLOWED_ATTR, xml); } } /* Merge configuration parameters */ if (cfg.ADD_TAGS) { if (typeof cfg.ADD_TAGS === 'function') { EXTRA_ELEMENT_HANDLING.tagCheck = cfg.ADD_TAGS; } else { if (ALLOWED_TAGS === DEFAULT_ALLOWED_TAGS) { ALLOWED_TAGS = clone(ALLOWED_TAGS); } addToSet(ALLOWED_TAGS, cfg.ADD_TAGS, transformCaseFunc); } } if (cfg.ADD_ATTR) { if (typeof cfg.ADD_ATTR === 'function') { EXTRA_ELEMENT_HANDLING.attributeCheck = cfg.ADD_ATTR; } else { if (ALLOWED_ATTR === DEFAULT_ALLOWED_ATTR) { ALLOWED_ATTR = clone(ALLOWED_ATTR); } addToSet(ALLOWED_ATTR, cfg.ADD_ATTR, transformCaseFunc); } } if (cfg.ADD_URI_SAFE_ATTR) { addToSet(URI_SAFE_ATTRIBUTES, cfg.ADD_URI_SAFE_ATTR, transformCaseFunc); } if (cfg.FORBID_CONTENTS) { if (FORBID_CONTENTS === DEFAULT_FORBID_CONTENTS) { FORBID_CONTENTS = clone(FORBID_CONTENTS); } addToSet(FORBID_CONTENTS, cfg.FORBID_CONTENTS, transformCaseFunc); } /* Add #text in case KEEP_CONTENT is set to true */ if (KEEP_CONTENT) { ALLOWED_TAGS['#text'] = true; } /* Add html, head and body to ALLOWED_TAGS in case WHOLE_DOCUMENT is true */ if (WHOLE_DOCUMENT) { addToSet(ALLOWED_TAGS, ['html', 'head', 'body']); } /* Add tbody to ALLOWED_TAGS in case tables are permitted, see #286, #365 */ if (ALLOWED_TAGS.table) { addToSet(ALLOWED_TAGS, ['tbody']); delete FORBID_TAGS.tbody; } if (cfg.TRUSTED_TYPES_POLICY) { if (typeof cfg.TRUSTED_TYPES_POLICY.createHTML !== 'function') { throw typeErrorCreate('TRUSTED_TYPES_POLICY configuration option must provide a "createHTML" hook.'); } if (typeof cfg.TRUSTED_TYPES_POLICY.createScriptURL !== 'function') { throw typeErrorCreate('TRUSTED_TYPES_POLICY configuration option must provide a "createScriptURL" hook.'); } // Overwrite existing TrustedTypes policy. trustedTypesPolicy = cfg.TRUSTED_TYPES_POLICY; // Sign local variables required by `sanitize`. emptyHTML = trustedTypesPolicy.createHTML(''); } else { // Uninitialized policy, attempt to initialize the internal dompurify policy. if (trustedTypesPolicy === undefined) { trustedTypesPolicy = _createTrustedTypesPolicy(trustedTypes, currentScript); } // If creating the internal policy succeeded sign internal variables. if (trustedTypesPolicy !== null && typeof emptyHTML === 'string') { emptyHTML = trustedTypesPolicy.createHTML(''); } } // Prevent further manipulation of configuration. // Not available in IE8, Safari 5, etc. if (freeze) { freeze(cfg); } CONFIG = cfg; }; /* Keep track of all possible SVG and MathML tags * so that we can perform the namespace checks * correctly. */ const ALL_SVG_TAGS = addToSet({}, [...svg$1, ...svgFilters, ...svgDisallowed]); const ALL_MATHML_TAGS = addToSet({}, [...mathMl$1, ...mathMlDisallowed]); /** * @param element a DOM element whose namespace is being checked * @returns Return false if the element has a * namespace that a spec-compliant parser would never * return. Return true otherwise. */ const _checkValidNamespace = function _checkValidNamespace(element) { let parent = getParentNode(element); // In JSDOM, if we're inside shadow DOM, then parentNode // can be null. We just simulate parent in this case. if (!parent || !parent.tagName) { parent = { namespaceURI: NAMESPACE, tagName: 'template' }; } const tagName = stringToLowerCase(element.tagName); const parentTagName = stringToLowerCase(parent.tagName); if (!ALLOWED_NAMESPACES[element.namespaceURI]) { return false; } if (element.namespaceURI === SVG_NAMESPACE) { // The only way to switch from HTML namespace to SVG // is via <svg>. If it happens via any other tag, then // it should be killed. if (parent.namespaceURI === HTML_NAMESPACE) { return tagName === 'svg'; } // The only way to switch from MathML to SVG is via` // svg if parent is either <annotation-xml> or MathML // text integration points. if (parent.namespaceURI === MATHML_NAMESPACE) { return tagName === 'svg' && (parentTagName === 'annotation-xml' || MATHML_TEXT_INTEGRATION_POINTS[parentTagName]); } // We only allow elements that are defined in SVG // spec. All others are disallowed in SVG namespace. return Boolean(ALL_SVG_TAGS[tagName]); } if (element.namespaceURI === MATHML_NAMESPACE) { // The only way to switch from HTML namespace to MathML // is via <math>. If it happens via any other tag, then // it should be killed. if (parent.namespaceURI === HTML_NAMESPACE) { return tagName === 'math'; } // The only way to switch from SVG to MathML is via // <math> and HTML integration points if (parent.namespaceURI === SVG_NAMESPACE) { return tagName === 'math' && HTML_INTEGRATION_POINTS[parentTagName]; } // We only allow elements that are defined in MathML // spec. All others are disallowed in MathML namespace. return Boolean(ALL_MATHML_TAGS[tagName]); } if (element.namespaceURI === HTML_NAMESPACE) { // The only way to switch from SVG to HTML is via // HTML integration points, and from MathML to HTML // is via MathML text integration points if (parent.namespaceURI === SVG_NAMESPACE && !HTML_INTEGRATION_POINTS[parentTagName]) { return false; } if (parent.namespaceURI === MATHML_NAMESPACE && !MATHML_TEXT_INTEGRATION_POINTS[parentTagName]) { return false; } // We disallow tags that are specific for MathML // or SVG and should never appear in HTML namespace return !ALL_MATHML_TAGS[tagName] && (COMMON_SVG_AND_HTML_ELEMENTS[tagName] || !ALL_SVG_TAGS[tagName]); } // For XHTML and XML documents that support custom namespaces if (PARSER_MEDIA_TYPE === 'application/xhtml+xml' && ALLOWED_NAMESPACES[element.namespaceURI]) { return true; } // The code should never reach this place (this means // that the element somehow got namespace that is not // HTML, SVG, MathML or allowed via ALLOWED_NAMESPACES). // Return false just in case. return false; }; /** * _forceRemove * * @param node a DOM node */ const _forceRemove = function _forceRemove(node) { arrayPush(DOMPurify.removed, { element: node }); try { // eslint-disable-next-line unicorn/prefer-dom-node-remove getParentNode(node).removeChild(node); } catch (_) { remove(node); } }; /** * _removeAttribute * * @param name an Attribute name * @param element a DOM node */ const _removeAttribute = function _removeAttribute(name, element) { try { arrayPush(DOMPurify.removed, { attribute: element.getAttributeNode(name), from: element }); } catch (_) { arrayPush(DOMPurify.removed, { attribute: null, from: element }); } element.removeAttribute(name); // We void attribute values for unremovable "is" attributes if (name === 'is') { if (RETURN_DOM || RETURN_DOM_FRAGMENT) { try { _forceRemove(element); } catch (_) {} } else { try { element.setAttribute(name, ''); } catch (_) {} } } }; /** * _initDocument * * @param dirty - a string of dirty markup * @return a DOM, filled with the dirty markup */ const _initDocument = function _initDocument(dirty) { /* Create a HTML document */ let doc = null; let leadingWhitespace = null; if (FORCE_BODY) { dirty = '<remove></remove>' + dirty; } else { /* If FORCE_BODY isn't used, leading whitespace needs to be preserved manually */ const matches = stringMatch(dirty, /^[\r\n\t ]+/); leadingWhitespace = matches && matches[0]; } if (PARSER_MEDIA_TYPE === 'application/xhtml+xml' && NAMESPACE === HTML_NAMESPACE) { // Root of XHTML doc must contain xmlns declaration (see https://www.w3.org/TR/xhtml1/normative.html#strict) dirty = '<html xmlns="http://www.w3.org/1999/xhtml"><head></head><body>' + dirty + '</body></html>'; } const dirtyPayload = trustedTypesPolicy ? trustedTypesPolicy.createHTML(dirty) : dirty; /* * Use the DOMParser API by default, fallback later if needs be * DOMParser not work for svg when has multiple root element. */ if (NAMESPACE === HTML_NAMESPACE) { try { doc = new DOMParser().parseFromString(dirtyPayload, PARSER_MEDIA_TYPE); } catch (_) {} } /* Use createHTMLDocument in case DOMParser is not available */ if (!doc || !doc.documentElement) { doc = implementation.createDocument(NAMESPACE, 'template', null); try { doc.documentElement.innerHTML = IS_EMPTY_INPUT ? emptyHTML : dirtyPayload; } catch (_) { // Syntax error if dirtyPayload is invalid xml } } const body = doc.body || doc.documentElement; if (dirty && leadingWhitespace) { body.insertBefore(document.createTextNode(leadingWhitespace), body.childNodes[0] || null); } /* Work on whole document or just its body */ if (NAMESPACE === HTML_NAMESPACE) { return getElementsByTagName.call(doc, WHOLE_DOCUMENT ? 'html' : 'body')[0]; } return WHOLE_DOCUMENT ? doc.documentElement : body; }; /** * Creates a NodeIterator object that you can use to traverse filtered lists of nodes or elements in a document. * * @param root The root element or node to start traversing on. * @return The created NodeIterator */ const _createNodeIterator = function _createNodeIterator(root) { return createNodeIterator.call(root.ownerDocument || root, root, // eslint-disable-next-line no-bitwise NodeFilter.SHOW_ELEMENT | NodeFilter.SHOW_COMMENT | NodeFilter.SHOW_TEXT | NodeFilter.SHOW_PROCESSING_INSTRUCTION | NodeFilter.SHOW_CDATA_SECTION, null); }; /** * _isClobbered * * @param element element to check for clobbering attacks * @return true if clobbered, false if safe */ const _isClobbered = function _isClobbered(element) { return element instanceof HTMLFormElement && (typeof element.nodeName !== 'string' || typeof element.textContent !== 'string' || typeof element.removeChild !== 'function' || !(element.attributes instanceof NamedNodeMap) || typeof element.removeAttribute !== 'function' || typeof element.setAttribute !== 'function' || typeof element.namespaceURI !== 'string' || typeof element.insertBefore !== 'function' || typeof element.hasChildNodes !== 'function'); }; /** * Checks whether the given object is a DOM node. * * @param value object to check whether it's a DOM node * @return true is object is a DOM node */ const _isNode = function _isNode(value) { return typeof Node === 'function' && value instanceof Node; }; function _executeHooks(hooks, currentNode, data) { arrayForEach(hooks, hook => { hook.call(DOMPurify, currentNode, data, CONFIG); }); } /** * _sanitizeElements * * @protect nodeName * @protect textContent * @protect removeChild * @param currentNode to check for permission to exist * @return true if node was killed, false if left alive */ const _sanitizeElements = function _sanitizeElements(currentNode) { let content = null; /* Execute a hook if present */ _executeHooks(hooks.beforeSanitizeElements, currentNode, null); /* Check if element is clobbered or can clobber */ if (_isClobbered(currentNode)) { _forceRemove(currentNode); return true; } /* Now let's check the element's type and name */ const tagName = transformCaseFunc(currentNode.nodeName); /* Execute a hook if present */ _executeHooks(hooks.uponSanitizeElement, currentNode, { tagName, allowedTags: ALLOWED_TAGS }); /* Detect mXSS attempts abusing namespace confusion */ if (SAFE_FOR_XML && currentNode.hasChildNodes() && !_isNode(currentNode.firstElementChild) && regExpTest(/<[/\w!]/g, currentNode.innerHTML) && regExpTest(/<[/\w!]/g, currentNode.textContent)) { _forceRemove(currentNode); return true; } /* Remove any occurrence of processing instructions */ if (currentNode.nodeType === NODE_TYPE.progressingInstruction) { _forceRemove(currentNode); return true; } /* Remove any kind of possibly harmful comments */ if (SAFE_FOR_XML && currentNode.nodeType === NODE_TYPE.comment && regExpTest(/<[/\w]/g, currentNode.data)) { _forceRemove(currentNode); return true; } /* Remove element if anything forbids its presence */ if (!(EXTRA_ELEMENT_HANDLING.tagCheck instanceof Function && EXTRA_ELEMENT_HANDLING.tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])) { /* Check if we have a custom element to handle */ if (!FORBID_TAGS[tagName] && _isBasicCustomElement(tagName)) { if (CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof RegExp && regExpTest(CUSTOM_ELEMENT_HANDLING.tagNameCheck, tagName)) { return false; } if (CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof Function && CUSTOM_ELEMENT_HANDLING.tagNameCheck(tagName)) { return false; } } /* Keep content except for bad-listed elements */ if (KEEP_CONTENT && !FORBID_CONTENTS[tagName]) { const parentNode = getParentNode(currentNode) || currentNode.parentNode; const childNodes = getChildNodes(currentNode) || currentNode.childNodes; if (childNodes && parentNode) { const childCount = childNodes.length; for (let i = childCount - 1; i >= 0; --i) { const childClone = cloneNode(childNodes[i], true); childClone.__removalCount = (currentNode.__removalCount || 0) + 1; parentNode.insertBefore(childClone, getNextSibling(currentNode)); } } } _forceRemove(currentNode); return true; } /* Check whether element has a valid namespace */ if (currentNode instanceof Element && !_checkValidNamespace(currentNode)) { _forceRemove(currentNode); return true; } /* Make sure that older browsers don't get fallback-tag mXSS */ if ((tagName === 'noscript' || tagName === 'noembed' || tagName === 'noframes') && regExpTest(/<\/no(script|embed|frames)/i, currentNode.innerHTML)) { _forceRemove(currentNode); return true; } /* Sanitize element content to be template-safe */ if (SAFE_FOR_TEMPLATES && currentNode.nodeType === NODE_TYPE.text) { /* Get the element's text content */ content = currentNode.textContent; arrayForEach([MUSTACHE_EXPR, ERB_EXPR, TMPLIT_EXPR], expr => { content = stringReplace(content, expr, ' '); }); if (currentNode.textContent !== content) { arrayPush(DOMPurify.removed, { element: currentNode.cloneNode() }); currentNode.textContent = content; } } /* Execute a hook if present */ _executeHooks(hooks.afterSanitizeElements, currentNode, null); return false; }; /** * _isValidAttribute * * @param lcTag Lowercase tag name of containing element. * @param lcName Lowercase attribute name. * @param value Attribute value. * @return Returns true if `value` is valid, otherwise false. */ // eslint-disable-next-line complexity const _isValidAttribute = function _isValidAttribute(lcTag, lcName, value) { /* Make sure attribute cannot clobber */ if (SANITIZE_DOM && (lcName === 'id' || lcName === 'name') && (value in document || value in formElement)) { return false; } /* Allow valid data-* attributes: At least one character after "-" (https://html.spec.whatwg.org/multipage/dom.html#embedding-custom-non-visible-data-with-the-data-*-attributes) XML-compatible (https://html.spec.whatwg.org/multipage/infrastructure.html#xml-compatible and http://www.w3.org/TR/xml/#d0e804) We don't need to check the value; it's always URI safe. */ if (ALLOW_DATA_ATTR && !FORBID_ATTR[lcName] && regExpTest(DATA_ATTR, lcName)) ; else if (ALLOW_ARIA_ATTR && regExpTest(ARIA_ATTR, lcName)) ; else if (EXTRA_ELEMENT_HANDLING.attributeCheck instanceof Function && EXTRA_ELEMENT_HANDLING.attributeCheck(lcName, lcTag)) ; else if (!ALLOWED_ATTR[lcName] || FORBID_ATTR[lcName]) { if ( // First condition does a very basic check if a) it's basically a valid custom element tagname AND // b) if the tagName passes whatever the user has configured for CUSTOM_ELEMENT_HANDLING.tagNameCheck // and c) if the attribute name passes whatever the user has configured for CUSTOM_ELEMENT_HANDLING.attributeNameCheck _isBasicCustomElement(lcTag) && (CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof RegExp && regExpTest(CUSTOM_ELEMENT_HANDLING.tagNameCheck, lcTag) || CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof Function && CUSTOM_ELEMENT_HANDLING.tagNameCheck(lcTag)) && (CUSTOM_ELEMENT_HANDLING.attributeNameCheck instanceof RegExp && regExpTest(CUSTOM_ELEMENT_HANDLING.attributeNameCheck, lcName) || CUSTOM_ELEMENT_HANDLING.attributeNameCheck instanceof Function && CUSTOM_ELEMENT_HANDLING.attributeNameCheck(lcName, lcTag)) || // Alternative, second condition checks if it's an `is`-attribute, AND // the value passes whatever the user has configured for CUSTOM_ELEMENT_HANDLING.tagNameCheck lcName === 'is' && CUSTOM_ELEMENT_HANDLING.allowCustomizedBuiltInElements && (CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof RegExp && regExpTest(CUSTOM_ELEMENT_HANDLING.tagNameCheck, value) || CUSTOM_ELEMENT_HANDLING.tagNameCheck instanceof Function && CUSTOM_ELEMENT_HANDLING.tagNameCheck(value))) ; else { return false; } /* Check value is safe. First, is attr inert? If so, is safe */ } else if (URI_SAFE_ATTRIBUTES[lcName]) ; else if (regExpTest(IS_ALLOWED_URI$1, stringReplace(value, ATTR_WHITESPACE, ''))) ; else if ((lcName === 'src' || lcName === 'xlink:href' || lcName === 'href') && lcTag !== 'script' && stringIndexOf(value, 'data:') === 0 && DATA_URI_TAGS[lcTag]) ; else if (ALLOW_UNKNOWN_PROTOCOLS && !regExpTest(IS_SCRIPT_OR_DATA, stringReplace(value, ATTR_WHITESPACE, ''))) ; else if (value) { return false; } else ; return true; }; /** * _isBasicCustomElement * checks if at least one dash is included in tagName, and it's not the first char * for more sophisticated checking see https://github.com/sindresorhus/validate-element-name * * @param tagName name of the tag of the node to sanitize * @returns Returns true if the tag name meets the basic criteria for a custom element, otherwise false. */ const _isBasicCustomElement = function _isBasicCustomElement(tagName) { return tagName !== 'annotation-xml' && stringMatch(tagName, CUSTOM_ELEMENT); }; /** * _sanitizeAttributes * * @protect attributes * @protect nodeName * @protect removeAttribute * @protect setAttribute * * @param currentNode to sanitize */ const _sanitizeAttributes = function _sanitizeAttributes(currentNode) { /* Execute a hook if present */ _executeHooks(hooks.beforeSanitizeAttributes, currentNode, null); const { attributes } = currentNode; /* Check if we have attributes; if not we might have a text node */ if (!attributes || _isClobbered(currentNode)) { return; } const hookEvent = { attrName: '', attrValue: '', keepAttr: true, allowedAttributes: ALLOWED_ATTR, forceKeepAttr: undefined }; let l = attributes.length; /* Go backwards over all attributes; safely remove bad ones */ while (l--) { const attr = attributes[l]; const { name, namespaceURI, value: attrValue } = attr; const lcName = transformCaseFunc(name); const initValue = attrValue; let value = name === 'value' ? initValue : stringTrim(initValue); /* Execute a hook if present */ hookEvent.attrName = lcName; hookEvent.attrValue = value; hookEvent.keepAttr = true; hookEvent.forceKeepAttr = undefined; // Allows developers to see this is a property they can set _executeHooks(hooks.uponSanitizeAttribute, currentNode, hookEvent); value = hookEvent.attrValue; /* Full DOM Clobbering protection via namespace isolation, * Prefix id and name attributes with `user-content-` */ if (SANITIZE_NAMED_PROPS && (lcName === 'id' || lcName === 'name')) { // Remove the attribute with this value _removeAttribute(name, currentNode); // Prefix the value and later re-create the attribute with the sanitized value value = SANITIZE_NAMED_PROPS_PREFIX + value; } /* Work around a security issue with comments inside attributes */ if (SAFE_FOR_XML && regExpTest(/((--!?|])>)|<\/(style|title|textarea)/i, value)) { _removeAttribute(name, currentNode); continue; } /* Make sure we cannot easily use animated hrefs, even if animations are allowed */ if (lcName === 'attributename' && stringMatch(value, 'href')) { _removeAttribute(name, currentNode); continue; } /* Did the hooks approve of the attribute? */ if (hookEvent.forceKeepAttr) { continue; } /* Did the hooks approve of the attribute? */ if (!hookEvent.keepAttr) { _removeAttribute(name, currentNode); continue; } /* Work around a security issue in jQuery 3.0 */ if (!ALLOW_SELF_CLOSE_IN_ATTR && regExpTest(/\/>/i, value)) { _removeAttribute(name, currentNode); continue; } /* Sanitize attribute content to be template-safe */ if (SAFE_FOR_TEMPLATES) { arrayForEach([MUSTACHE_EXPR, ERB_EXPR, TMPLIT_EXPR], expr => { value = stringReplace(value, expr, ' '); }); } /* Is `value` valid for this attribute? */ const lcTag = transformCaseFunc(currentNode.nodeName); if (!_isValidAttribute(lcTag, lcName, value)) { _removeAttribute(name, currentNode); continue; } /* Handle attributes that require Trusted Types */ if (trustedTypesPolicy && typeof trustedTypes === 'object' && typeof trustedTypes.getAttributeType === 'function') { if (namespaceURI) ; else { switch (trustedTypes.getAttributeType(lcTag, lcName)) { case 'TrustedHTML': { value = trustedTypesPolicy.createHTML(value); break; } case 'TrustedScriptURL': { value = trustedTypesPolicy.createScriptURL(value); break; } } } } /* Handle invalid data-* attribute set by try-catching it */ if (value !== initValue) { try { if (namespaceURI) { currentNode.setAttributeNS(namespaceURI, name, value); } else { /* Fallback to setAttribute() for browser-unrecognized namespaces e.g. "x-schema". */ currentNode.setAttribute(name, value); } if (_isClobbered(currentNode)) { _forceRemove(currentNode); } else { arrayPop(DOMPurify.removed); } } catch (_) { _removeAttribute(name, currentNode); } } } /* Execute a hook if present */ _executeHooks(hooks.afterSanitizeAttributes, currentNode, null); }; /** * _sanitizeShadowDOM * * @param fragment to iterate over recursively */ const _sanitizeShadowDOM = function _sanitizeShadowDOM(fragment) { let shadowNode = null; const shadowIterator = _createNodeIterator(fragment); /* Execute a hook if present */ _executeHooks(hooks.beforeSanitizeShadowDOM, fragment, null); while (shadowNode = shadowIterator.nextNode()) { /* Execute a hook if present */ _executeHooks(hooks.uponSanitizeShadowNode, shadowNode, null); /* Sanitize tags and elements */ _sanitizeElements(shadowNode); /* Check attributes next */ _sanitizeAttributes(shadowNode); /* Deep shadow DOM detected */ if (shadowNode.content instanceof DocumentFragment) { _sanitizeShadowDOM(shadowNode.content); } } /* Execute a hook if present */ _executeHooks(hooks.afterSanitizeShadowDOM, fragment, null); }; // eslint-disable-next-line complexity DOMPurify.sanitize = function (dirty) { let cfg = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {}; let body = null; let importedNode = null; let currentNode = null; let returnNode = null; /* Make sure we have a string to sanitize. DO NOT return early, as this will return the wrong type if the user has requested a DOM object rather than a string */ IS_EMPTY_INPUT = !dirty; if (IS_EMPTY_INPUT) { dirty = '<!-->'; } /* Stringify, in case dirty is an object */ if (typeof dirty !== 'string' && !_isNode(dirty)) { if (typeof dirty.toString === 'function') { dirty = dirty.toString(); if (typeof dirty !== 'string') { throw typeErrorCreate('dirty is not a string, aborting'); } } else { throw typeErrorCreate('toString is not a function'); } } /* Return dirty HTML if DOMPurify cannot run */ if (!DOMPurify.isSupported) { return dirty; } /* Assign config vars */ if (!SET_CONFIG) { _parseConfig(cfg); } /* Clean up removed elements */ DOMPurify.removed = []; /* Check if dirty is correctly typed for IN_PLACE */ if (typeof dirty === 'string') { IN_PLACE = false; } if (IN_PLACE) { /* Do some early pre-sanitization to avoid unsafe root nodes */ if (dirty.nodeName) { const tagName = transformCaseFunc(dirty.nodeName); if (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName]) { throw typeErrorCreate('root node is forbidden and cannot be sanitized in-place'); } } } else if (dirty instanceof Node) { /* If dirty is a DOM element, append to an empty document to avoid elements being stripped by the parser */ body = _initDocument('<!---->'); importedNode = body.ownerDocument.importNode(dirty, true); if (importedNode.nodeType === NODE_TYPE.element && importedNode.nodeName === 'BODY') { /* Node is already a body, use as is */ body = importedNode; } else if (importedNode.nodeName === 'HTML') { body = importedNode; } else { // eslint-disable-next-line unicorn/prefer-dom-node-append body.appendChild(importedNode); } } else { /* Exit directly if we have nothing to do */ if (!RETURN_DOM && !SAFE_FOR_TEMPLATES && !WHOLE_DOCUMENT && // eslint-disable-next-line unicorn/prefer-includes dirty.indexOf('<') === -1) { return trustedTypesPolicy && RETURN_TRUSTED_TYPE ? trustedTypesPolicy.createHTML(dirty) : dirty; } /* Initialize the document to work on */ body = _initDocument(dirty); /* Check we have a DOM node from the data */ if (!body) { return RETURN_DOM ? null : RETURN_TRUSTED_TYPE ? emptyHTML : ''; } } /* Remove first element node (ours) if FORCE_BODY is set */ if (body && FORCE_BODY) { _forceRemove(body.firstChild); } /* Get node iterator */ const nodeIterator = _createNodeIterator(IN_PLACE ? dirty : body); /* Now start iterating over the created document */ while (currentNode = nodeIterator.nextNode()) { /* Sanitize tags and elements */ _sanitizeElements(currentNode); /* Check attributes next */ _sanitizeAttributes(currentNode); /* Shadow DOM detected, sanitize it */ if (currentNode.content instanceof DocumentFragment) { _sanitizeShadowDOM(currentNode.content); } } /* If we sanitized `dirty` in-place, return it. */ if (IN_PLACE) { return dirty; } /* Return sanitized string or DOM */ if (RETURN_DOM) { if (RETURN_DOM_FRAGMENT) { returnNode = createDocumentFragment.call(body.ownerDocument); while (body.firstChild) { // eslint-disable-next-line unicorn/prefer-dom-node-append returnNode.appendChild(body.firstChild); } } else { returnNode = body; } if (ALLOWED_ATTR.shadowroot || ALLOWED_ATTR.shadowrootmode) { /* AdoptNode() is not used because internal state is not reset (e.g. the past names map of a HTMLFormElement), this is safe in theory but we would rather not risk another attack vector. The state that is cloned by importNode() is explicitly defined by the specs. */ returnNode = importNode.call(originalDocument, returnNode, true); } return returnNode; } let serializedHTML = WHOLE_DOCUMENT ? body.outerHTML : body.innerHTML; /* Serialize doctype if allowed */ if (WHOLE_DOCUMENT && ALLOWED_TAGS['!doctype'] && body.ownerDocument && body.ownerDocument.doctype && body.ownerDocument.doctype.name && regExpTest(DOCTYPE_NAME, body.ownerDocument.doctype.name)) { serializedHTML = '<!DOCTYPE ' + body.ownerDocument.doctype.name + '>\n' + serializedHTML; } /* Sanitize final string template-safe */ if (SAFE_FOR_TEMPLATES) { arrayForEach([MUSTACHE_EXPR, ERB_EXPR, TMPLIT_EXPR], expr => { serializedHTML = stringReplace(serializedHTML, expr, ' '); }); } return trustedTypesPolicy && RETURN_TRUSTED_TYPE ? trustedTypesPolicy.createHTML(serializedHTML) : serializedHTML; }; DOMPurify.setConfig = function () { let cfg = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {}; _parseConfig(cfg); SET_CONFIG = true; }; DOMPurify.clearConfig = function () { CONFIG = null; SET_CONFIG = false; }; DOMPurify.isValidAttribute = function (tag, attr, value) { /* Initialize shared config vars if necessary. */ if (!CONFIG) { _parseConfig({}); } const lcTag = transformCaseFunc(tag); const lcName = transformCaseFunc(attr); return _isValidAttribute(lcTag, lcName, value); }; DOMPurify.addHook = function (entryPoint, hookFunction) { if (typeof hookFunction !== 'function') { return; } arrayPush(hooks[entryPoint], hookFunction); }; DOMPurify.removeHook = function (entryPoint, hookFunction) { if (hookFunction !== undefined) { const index = arrayLastIndexOf(hooks[entryPoint], hookFunction); return index === -1 ? undefined : arraySplice(hooks[entryPoint], index, 1)[0]; } return arrayPop(hooks[entryPoint]); }; DOMPurify.removeHooks = function (entryPoint) { hooks[entryPoint] = []; }; DOMPurify.removeAllHooks = function () { hooks = _createHooksMap(); }; return DOMPurify; } var purify = createDOMPurify(); module.exports = purify; //# sourceMappingURL=purify.cjs.js.map /***/ }) }]); //# sourceMappingURL=6caa76d2f6eec6c4e665.bundle.js.map
Save
cmd:
run