Skip to content

Commit 1c0db07

Browse files
committed
update README.md to document raw() function and RawHtml class usage
1 parent df1dad6 commit 1c0db07

1 file changed

Lines changed: 28 additions & 1 deletion

File tree

‎README.md‎

Lines changed: 28 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -196,6 +196,26 @@ echo div(text: $userInput);
196196
// Output: <div>&lt;script&gt;alert("hacked")&lt;/script&gt;</div>
197197
```
198198

199+
### Raw HTML when you need it
200+
201+
Sometimes you have trusted HTML from a Markdown parser, CMS, or other source. Use `raw()` to inject it unescaped:
202+
203+
```php
204+
use function Epic64\Elem\raw;
205+
use function Epic64\Elem\div;
206+
207+
// Output from a Markdown parser
208+
$htmlFromMarkdown = '<p>Hello <strong>world</strong>!</p>';
209+
210+
// Inject it directly into your Elem tree
211+
echo div(class: 'content')(
212+
raw($htmlFromMarkdown)
213+
);
214+
// Output: <div class="content"><p>Hello <strong>world</strong>!</p></div>
215+
```
216+
217+
> ⚠️ **Warning:** Only use `raw()` with trusted content. Never pass user input directly to `raw()` - that defeats the XSS protection!
218+
199219
### LLM-friendly
200220

201221
Using AI to generate HTML? Elem's structure catches mistakes that would slip through with templates:
@@ -470,7 +490,7 @@ $card->__invoke(
470490
The `__invoke` method accepts variadic arguments, so you can pass any number of children. It also handles arrays and any `iterable`, which is why `array_map()`, `list_of()`, and Laravel collections all work seamlessly:
471491

472492
```php
473-
public function __invoke(DOMNode|Element|string|iterable|null ...$children): static
493+
public function __invoke(DOMNode|Element|RawHtml|string|iterable|null ...$children): static
474494
```
475495

476496
## API Reference
@@ -485,6 +505,7 @@ All element classes extend the base `Element` class and provide fluent interface
485505
- **Forms**: `Form`, `Input`, `Button`, `Label`, `Textarea`, `Select`, `Option`
486506
- **Lists**: `UnorderedList`, `OrderedList`, `ListItem`
487507
- **Tables**: `Table`, `TableRow`, `TableCell`, `TableHeader`
508+
- **Special**: `RawHtml` - Holds unescaped HTML content (use via `raw()` function)
488509

489510
### Common Methods
490511

@@ -498,6 +519,12 @@ All elements support:
498519
- `->toHtml(bool $pretty = false)` - Output HTML
499520
- `->toPrettyHtml()` - Output formatted HTML (called automatically in __toString)
500521

522+
### Helper Functions
523+
524+
- `el(string $tag)` - Create a generic element with any tag name
525+
- `raw(string $html)` - Create a `RawHtml` instance for injecting unescaped HTML
526+
- `list_of(iterable $items)` - Create a fluent collection for mapping/filtering
527+
501528
## Demo Server
502529

503530
The `examples/` directory contains interactive demos showcasing the library's features.

0 commit comments

Comments
 (0)