logoalt Hacker News

entunoyesterday at 5:16 PM0 repliesview on HN

If that'd been the design from the start, then sure. But it's not at all obvious that setHTML is safe with arbitrary user input (for a given value of "safe") and innerHTML is dangerous.