Skip to content

Conversation

Shivam7-1
Copy link
Contributor

By using innerText, it will avoid the risk of HTML injection, as these properties automatically escape any HTML special characters in the provided text. This helps prevent cross-site scripting (XSS) vulnerabilities by treating the input as plain text rather than interpreted HTML.

@Shivam7-1
Copy link
Contributor Author

Hi @MarkusBordihn Could You Please Review This PR
Thanks

@MarkusBordihn MarkusBordihn merged commit e390dfb into google:main Apr 26, 2024
@MarkusBordihn
Copy link
Member

Thank you for your thorough explanation regarding the use of innerText to mitigate the risk of HTML injection and potential cross-site scripting (XSS) vulnerabilities.
Given that the text provided is static and does not involve any user input, the risk of XSS vulnerabilities is indeed minimal in this specific use-case.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants