page-integrity-js
Version:
A library for monitoring and controlling DOM mutations and script execution, essential for PCI DSS compliance and security audits
92 lines (91 loc) • 3.17 kB
TypeScript
/**
* Page Integrity JS
* A library for ensuring webpage content integrity by verifying that content updates
* come from first-party JavaScript.
*
* @packageDocumentation
*/
import { PageIntegrityConfig } from './types';
import { ScriptBlocker } from './script-blocking';
import { CacheManager } from './utils/cache-manager';
export type MutationType = 'insert' | 'update' | 'remove';
export type ElementType = 'div' | 'span' | 'p' | 'a' | 'img' | 'button';
export type ScriptSource = 'inline' | 'external' | 'extension' | 'unknown';
export interface ScriptInfo {
/** Unique hash identifier for the script */
hash: string;
/** Origin of the script */
origin: string;
/** Script type (e.g., 'text/javascript') */
type: string;
/** Order in which the script was loaded */
loadOrder: number;
/** List of script dependencies */
dependencies: string[];
/** Source of the script execution */
source: ScriptSource;
/** Whether the script is from a Chrome extension */
isExtension: boolean;
/** Whether the script is first-party (part of the original HTML) */
isFirstParty: boolean;
}
export interface MutationContext {
/** Parent element of the mutated element */
parentElement: Element | null;
/** Previous sibling element */
previousSibling: Element | null;
/** Next sibling element */
nextSibling: Element | null;
}
export interface MutationInfo {
/** Target element that was mutated */
target: Element;
/** Type of mutation performed */
type: MutationType;
/** Timestamp of the mutation */
timestamp: number;
/** Hash of the script that performed the mutation */
scriptHash: string;
/** Context information about the mutation */
context: MutationContext;
}
export interface AllowedMutations {
/** Allowed HTML element types */
elementTypes: ElementType[];
/** Allowed HTML attributes */
attributes: string[];
/** Regex patterns for allowed attributes */
patterns: RegExp[];
}
export declare function mergeConfig(defaults: PageIntegrityConfig, config: PageIntegrityConfig): PageIntegrityConfig;
export declare function initScriptBlocker(config: PageIntegrityConfig, cacheManager: CacheManager): ScriptBlocker;
export declare function exposeGlobally(cls: any, name: string): void;
/**
* Main class for monitoring and enforcing page integrity.
*
* Example usage:
* ```js
* const pi = new PageIntegrity({
* blacklistedHosts: ['evil.com'],
* whitelistedHosts: ['trusted.com'],
* onBlocked: (info) => { ... }
* });
* ```
*/
export declare class PageIntegrity {
private config;
private scriptBlocker;
private cacheManager;
/**
* Create a new PageIntegrity instance.
* @param config Configuration options for script and DOM mutation monitoring.
*/
constructor(config: PageIntegrityConfig);
/**
* Update the configuration for script and DOM mutation monitoring.
* @param newConfig Partial configuration to merge with the current config.
*/
updateConfig(newConfig: Partial<PageIntegrityConfig>): void;
private handleScript;
}
export * from './types';