pub fn sanitize_with(html: &str, tags: &[&str], attributes: &[&str]) -> StringExpand description
Like sanitize, with your own allowed tags and attributes (Rails’ sanitize(html, tags:, attributes:)).
Names are lowercase. Script-like elements, event handlers and unsafe URL schemes stay out whatever the lists say.
§Examples
use ocre::security::sanitize_with;
let html = r#"<p class="x"><a href="/about" title="About">About</a> <img src="x.png"></p>"#;
assert_eq!(sanitize_with(html, &["a"], &["href"]), r#"<a href="/about">About</a> "#);