Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Web Standards
@webstandards_dev@mastodon.social  ·  activity timestamp 3 weeks ago

setHTML(), Trusted Types and the Sanitizer API. Ollie Williams explains how the new setHTML() method and Sanitizer API help prevent XSS by safely inserting HTML into the DOM. Combined with the Trusted Types API, they provide a modern, configurable way to control what elements and attributes are allowed, eventually replacing libraries like DOMPurify. Supported in Firefox Nightly and Chrome Canary. #security #html

https://olliewilliams.xyz/blog/sanitizer/

setHTML(), Trusted Types and the Sanitizer API

Avoiding cross-site scripting (XSS) attacks with new web APIs
Oct 29, 2025. setHTML(), Trusted Types and the Sanitizer API. olliewilliams.xyz
Oct 29, 2025. setHTML(), Trusted Types and the Sanitizer API. olliewilliams.xyz
Oct 29, 2025. setHTML(), Trusted Types and the Sanitizer API. olliewilliams.xyz
  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login