# HtmlEmbedConfig

interface

The configuration of the HTML embed feature.

```typescript
ClassicEditor
  .create( {
	htmlEmbed: ... // HTML embed feature options.
  } )
	 .then( ... )
  .catch( ... );
```

See [all editor options](module_core_editor_editorconfig-EditorConfig.md).

[See source](https://github.com/ckeditor/ckeditor5/blob/master/packages/ckeditor5-html-embed/src/htmlembedconfig.ts#L24)

<a id="properties">

## Properties

<a id="member-sanitizeHtml">

### `sanitizeHtml?: ( html: string ) => HtmlEmbedSanitizeOutput`

Callback used to sanitize the HTML provided by the user in HTML embed widget when it is previewed inside the editor.

We strongly recommend overwriting the default function to avoid XSS vulnerabilities.

Read more about the security aspect of this feature in the ["Security"](../features/html/html-embed.md#security) section of the [HTML embed](../features/html/html-embed.md) feature guide.

The function receives the input HTML (as a string), and should return an object that matches the [`HtmlEmbedSanitizeOutput`](module_html-embed_htmlembedconfig-HtmlEmbedSanitizeOutput.md) interface.

```typescript
ClassicEditor
  .create( {
	htmlEmbed: {
	  showPreviews: true,
	  sanitizeHtml( inputHtml ) {
		// Strip unsafe elements and attributes, e.g.:
		// the `<script>` elements and `on*` attributes.
		const outputHtml = sanitize( inputHtml );

		return {
		  html: outputHtml,
		  // true or false depending on whether the sanitizer stripped anything.
		  hasChanged: ...
		};
	  },
	}
  } )
  .then( ... )
  .catch( ... );
```

**Note:** The function is used only when the feature [is configured to render previews](#member-showPreviews).

[See source](https://github.com/ckeditor/ckeditor5/blob/master/packages/ckeditor5-html-embed/src/htmlembedconfig.ts#L76)

<a id="member-showPreviews">

### `showPreviews?: boolean`

Whether the feature should render previews of the embedded HTML.

When set to `true`, the feature will produce a preview of the inserted HTML based on a sanitized version of the HTML provided by the user.

The function responsible for sanitizing the HTML needs to be specified in [`config.htmlEmbed.sanitizeHtml()`](#member-sanitizeHtml).

Read more about the security aspect of this feature in the ["Security"](../features/html/html-embed.md#security) section of the [HTML embed](../features/html/html-embed.md) feature guide.

[See source](https://github.com/ckeditor/ckeditor5/blob/master/packages/ckeditor5-html-embed/src/htmlembedconfig.ts#L38)

---

Full index of the CKEditor 5 API reference: [llms.txt](llms.txt)
