Thu 04 Jan 2024 11:54

Dear and or people,

Hello.

What's the safe, framework-less, way to render untrusted user input in a web component via the light (non-shadow) DOM?

`createContextualFragment` is powerful but hard to make safe if you interpolate user supplied input into a bunch of markup text.

Thank you.

https://mastodon.green/@d6y/111697543268977036