web api instance method
Sanitizer: removeAttribute() method
The removeAttribute() method of the Sanitizer interface sets an attribute to be removed from all elements when the sanitizer is used.
The method can be used with either an allow configuration or a remove configuration.
If used with a remove configuration, the specified attribute is added to the removeAttributes array.
If used with an allow configuration, the attribute is removed from the attributes array (if present).
Note that to allow/disallow attributes only on specific elements use allowElement().
Syntax
removeAttribute(attribute)
Parameters
attribute- : A string indicating the name of the attribute to be disallowed globally on elements, or an object with the following properties:
name- : A string containing the name of the attribute.
namespaceOptional- : A string containing the namespace of the attribute, which defaults to
null.
- : A string containing the namespace of the attribute, which defaults to
- : A string indicating the name of the attribute to be disallowed globally on elements, or an object with the following properties:
Return value
true if the operation changed the configuration to disallow the attribute, and false if the attribute was already disallowed.
Note that false might be returned if the internal configuration:
- defines a
removeAttributesarray that already contains the specified attribute (and is hence already filtered) - instead defines an
attributesarray that already omits the attribute (and is hence already disallowed)
Examples
How to disallow specific attributes
This example shows how removeAttribute() is used to specify that an attribute is should be removed from elements.
<pre id="log"></pre>
#log {
height: 300px;
overflow: scroll;
padding: 0.5rem;
border: 1px solid black;
}
const logElement = document.querySelector("#log");
function log(text) {
logElement.textContent = text;
}
JavaScript
The code first creates a new Sanitizer object that initially specifies no attributes or elements.
We then call removeAttribute() with the attributes title and mathcolor.
if ("Sanitizer" in window) {
// Create sanitizer that allows
const sanitizer = new Sanitizer({
removeAttributes: [],
});
// Remove the title attribute
sanitizer.removeAttribute("title");
// Remove the mathcolor attribute
sanitizer.removeAttribute("mathcolor");
// Log the sanitizer configuration
let sanitizerConfig = sanitizer.get();
log(JSON.stringify(sanitizerConfig, null, 2));
} else {
log("The HTML Sanitizer API is NOT supported in this browser.");
}
Results
The final configuration is logged below.
Note how both attributes are now added to the removeAttributes list (these attributes will removed if present on elements when the sanitizer is used).