Oh, that's nice-to-have. Good work, Mozilla.
It would close the loop better if you could also use policy to switch off innerHTML in a given page, but definitely a step in the right direction for plain-JavaScript applications.