Sanitizer: get() method

Limited availability

This feature is not Baseline because it does not work in some of the most widely-used browsers.

The get() method of the Sanitizer interface returns a SanitizerConfig dictionary instance that represents the current Sanitizer configuration.

This may be used to create a sanitizer that is slightly modified from the default; by first getting and then modifying the default Sanitizer configuration, and then using it to construct a new Sanitizer.

The returned configuration can also be used to inspect the configuration, and can be passed directly the HTML parsing functions. Note however that it will be more efficient to pass a Sanitizer rather than a configuration dictionary, particularly where the Sanitizer is to be used multiple times.

Syntax

js
get()

Parameters

None

Return value

A SanitizerConfig.

Examples

Getting a configuration

This example shows how you might create a new sanitizer and get its configuration.

JavaScript

The following code tests whether the Sanitizer interface is supported, and if so creates a new Sanitizer object using a simple SanitizerConfig that allows the HTML elements: <div>, <p>, <span>, <script>. It then gets and logs the configuration.

js
// Create sanitizer using SanitizerConfig
const sanitizer = new Sanitizer({ elements: ["div", "p", "span", "script"] });

// Get current configuration
const sanitizerConfig = sanitizer.get();

log(JSON.stringify(sanitizerConfig, null, 2));

Results

The output is logged below. Note that the same elements set when constructing the sanitizer are returned, but the new elements also have a namespace. Note also here that comments and data attributes will be allowed.

Getting the default sanitizer

This example shows how you can get the configuration for the default Sanitizer. This might then be modified and used to create a new Sanitizer that meets your specific needs.

JavaScript

The following code tests whether the Sanitizer interface is supported. It then creates the default Sanitizer, passing no options, and then gets and logs the configuration.

js
// Create default sanitizer
const sanitizer = new Sanitizer();

// Get default configuration
const defaultConfig = sanitizer.get();

log(JSON.stringify(defaultConfig, null, 2));

Results

The default sanitizer configuration is logged below. Note that the default configuration is quite big, allowing many elements and attributes.

Specifications

Specification
HTML Sanitizer API
# dom-sanitizer-get

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
get
Chrome – Full support
Chrome 146 (Release date: 2026-03-10)
footnote Full support
Edge – Full support
Edge 146 (Release date: 2026-03-13)
footnote Full support
Firefox – Full support
Firefox 148 (Release date: 2026-02-24)
footnote Full support
Opera – Full support
Opera 130 (Release date: 2026-04-08)
footnote Full support
Safari – No support
Safari
footnote No support
Chrome Android – Full support
Chrome Android 146 (Release date: 2026-03-10)
footnote Full support
Firefox for Android – Full support
Firefox for Android 148 (Release date: 2026-02-24)
footnote Full support
Opera Android – Full support
Opera Android 97 (Release date: 2026-04-16)
footnote Full support
Safari on iOS – No support
Safari on iOS
footnote No support
Samsung Internet – No support
Samsung Internet
footnote No support
WebView Android – Full support
WebView Android 146 (Release date: 2026-03-10)
footnote Full support
WebView on iOS – No support
WebView on iOS
footnote No support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support