跳到主要内容

dsh-html-escape

已验证

dsh-html-escape · v0.1.0 · MIT

HTML 实体编解码:转义/反转义 HTML 特殊字符与常用实体

安装

dsh plugin add dsh-html-escape

dsh --profile default --dump-config 确认 layer 已生效 —— 参见安装指南

源码

发布到 npm 但没有公开仓库。安装前请检查包内容。

标签

说明文档

dsh-html-escape · HTML 实体编解码

转义/反转义 HTML 特殊字符与常用实体。纯 Node 实现。

提供的工具

工具 作用
html_escape 转义 & < > " '
html_unescape 反转义实体

安装

dsh plugin add dsh-html-escape

安装后在 profile 的 package.jsondsh.profile.bundles 中加入 "dsh-html-escape"

用法示例

把这段用户输入转义,防止 XSS
→ 调用 html_escape(text="<script>alert(1)</script>")