UNPKG

page-integrity-js

Version:

A library for monitoring and controlling DOM mutations and script execution, essential for PCI DSS compliance and security audits

92 lines (91 loc) 3.17 kB
/** * Page Integrity JS * A library for ensuring webpage content integrity by verifying that content updates * come from first-party JavaScript. * * @packageDocumentation */ import { PageIntegrityConfig } from './types'; import { ScriptBlocker } from './script-blocking'; import { CacheManager } from './utils/cache-manager'; export type MutationType = 'insert' | 'update' | 'remove'; export type ElementType = 'div' | 'span' | 'p' | 'a' | 'img' | 'button'; export type ScriptSource = 'inline' | 'external' | 'extension' | 'unknown'; export interface ScriptInfo { /** Unique hash identifier for the script */ hash: string; /** Origin of the script */ origin: string; /** Script type (e.g., 'text/javascript') */ type: string; /** Order in which the script was loaded */ loadOrder: number; /** List of script dependencies */ dependencies: string[]; /** Source of the script execution */ source: ScriptSource; /** Whether the script is from a Chrome extension */ isExtension: boolean; /** Whether the script is first-party (part of the original HTML) */ isFirstParty: boolean; } export interface MutationContext { /** Parent element of the mutated element */ parentElement: Element | null; /** Previous sibling element */ previousSibling: Element | null; /** Next sibling element */ nextSibling: Element | null; } export interface MutationInfo { /** Target element that was mutated */ target: Element; /** Type of mutation performed */ type: MutationType; /** Timestamp of the mutation */ timestamp: number; /** Hash of the script that performed the mutation */ scriptHash: string; /** Context information about the mutation */ context: MutationContext; } export interface AllowedMutations { /** Allowed HTML element types */ elementTypes: ElementType[]; /** Allowed HTML attributes */ attributes: string[]; /** Regex patterns for allowed attributes */ patterns: RegExp[]; } export declare function mergeConfig(defaults: PageIntegrityConfig, config: PageIntegrityConfig): PageIntegrityConfig; export declare function initScriptBlocker(config: PageIntegrityConfig, cacheManager: CacheManager): ScriptBlocker; export declare function exposeGlobally(cls: any, name: string): void; /** * Main class for monitoring and enforcing page integrity. * * Example usage: * ```js * const pi = new PageIntegrity({ * blacklistedHosts: ['evil.com'], * whitelistedHosts: ['trusted.com'], * onBlocked: (info) => { ... } * }); * ``` */ export declare class PageIntegrity { private config; private scriptBlocker; private cacheManager; /** * Create a new PageIntegrity instance. * @param config Configuration options for script and DOM mutation monitoring. */ constructor(config: PageIntegrityConfig); /** * Update the configuration for script and DOM mutation monitoring. * @param newConfig Partial configuration to merge with the current config. */ updateConfig(newConfig: Partial<PageIntegrityConfig>): void; private handleScript; } export * from './types';