setHTML(), Trusted Types and the Sanitizer API. Ollie Williams explains how the new setHTML() method and Sanitizer API help prevent XSS by safely inserting HTML into the DOM. Combined with the Trusted Types API, they provide a modern, configurable way to control what elements and attributes are allowed, eventually replacing libraries like DOMPurify. Supported in Firefox Nightly and Chrome Canary.

olliewilliams.xyz/blog/sanitiz

Oct 29, 2025. setHTML(), Trusted Types and the Sanitizer API. olliewilliams.xyz
0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/ap/users/115452321018560572/statuses/115485898209253754 on your instance and quote it. (Note that quoting is not supported in Mastodon.)