import dompurify = require('dompurify'); dompurify.sanitize(''); dompurify.addHook('beforeSanitizeElements', (el, data, config) => undefined); //examples from the DOMPurify README let dirty = '
Totally safe
Totally not safe
'; let str: string; let elem: HTMLElement; let frag: DocumentFragment; // allow only str = dompurify.sanitize(dirty, { ALLOWED_TAGS: ['b'] }); // allow only andwith style attributes (for whatever reason) str = dompurify.sanitize(dirty, { ALLOWED_TAGS: ['b', 'q'], ALLOWED_ATTR: ['style'] }); // leave all as it is but forbid