Function html

  • Parse HTML Content to remove XSS (if used properly)

    Parameters

    • parts: TemplateStringsArray
    • Rest ...variables: HTMLContent[]

    Returns string

    Example

    const userInput = '<script>alert("OOps")</script>'

    const insecure = `
    <p>Message:</p>
    <p>${userInput}</p>
    ` // XSS Vulnerable

    const secure = html`
    <p>Message:</p>
    <p>${userInput}</p>
    ` // XSS Safe

    Since

    8.7.0