tanem / svg-injector

:syringe: Fast, caching, dynamic inline SVG DOM injection library.
https://npm.im/@tanem/svg-injector
MIT License
101 stars 14 forks source link
dom html images img javascript scalable-vector-graphics svg typescript

svg-injector

npm version build status coverage status npm downloads minzipped size

A fast, caching, dynamic inline SVG DOM injection library.

Background

There are a number of ways to use SVG on a page (object, embed, iframe, img, CSS background-image) but to unlock the full potential of SVG, including full element-level CSS styling and evaluation of embedded JavaScript, the full SVG markup must be included directly in the DOM.

Wrangling and maintaining a bunch of inline SVG on your pages isn't anyone's idea of good time, so SVGInjector lets you work with simple tag elements and does the heavy lifting of swapping in the SVG markup inline for you.

Basic Usage

<div id="inject-me" data-src="https://github.com/tanem/svg-injector/raw/master/icon.svg"></div>
import { SVGInjector } from '@tanem/svg-injector'

SVGInjector(document.getElementById('inject-me'))

Avoiding XSS

Be careful when injecting arbitrary third-party SVGs into the DOM, as this opens the door to XSS attacks. If you must inject third-party SVGs, it is highly recommended to sanitize the SVG before injecting. The following example uses DOMPurify to strip out attributes and tags that can execute arbitrary JavaScript. Note that this can alter the behavior of the SVG.

import { SVGInjector } from '@tanem/svg-injector'
import DOMPurify from 'dompurify'

SVGInjector(document.getElementById('inject-me'), {
  beforeEach(svg) {
    DOMPurify.sanitize(svg, {
      IN_PLACE: true,
      USE_PROFILES: { svg: true, svgFilters: true },
    })
  },
})

Live Examples

API

Arguments

Example

<div class="inject-me" data-src="https://github.com/tanem/svg-injector/raw/master/icon-one.svg"></div>
<div class="inject-me" data-src="https://github.com/tanem/svg-injector/raw/master/icon-two.svg"></div>
import { SVGInjector } from '@tanem/svg-injector'

SVGInjector(document.getElementsByClassName('inject-me'), {
  afterAll(elementsLoaded) {
    console.log(`injected ${elementsLoaded} elements`)
  },
  afterEach(err, svg) {
    if (err) {
      throw err
    }
    console.log(`injected ${svg.outerHTML}`)
  },
  beforeEach(svg) {
    svg.setAttribute('stroke', 'red')
  },
  cacheRequests: false,
  evalScripts: 'once',
  httpRequestWithCredentials: false,
  renumerateIRIElements: false,
})

Installation

⚠️This library uses Array.from(), so if you're targeting browsers that don't support that method, you'll need to ensure an appropriate polyfill is included manually. See this issue comment for further detail.

$ npm install @tanem/svg-injector

There are also UMD builds available via unpkg:

Credit

This is a fork of a library originally developed by Waybury for use in iconic.js, part of the Iconic icon system.

License

MIT