logoalt Hacker News

evilpieyesterday at 2:47 PM0 repliesview on HN

Using an allowlist based Sanitizer you are definitely less likely to shoot yourself in the foot, but as long as you use setHTML you can't introduce XSS at least.