Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Anything with user input I just use innerText.

Or a simple escapeHTML function within the innerHTML - but I prefer innerText in a separate pass, as using escapeHTML as a pattern gives an opportunity to forget to use it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: