diff --git a/src/routes/solid-start/guides/security.mdx b/src/routes/solid-start/guides/security.mdx index 7f0593955..4839d459e 100644 --- a/src/routes/solid-start/guides/security.mdx +++ b/src/routes/solid-start/guides/security.mdx @@ -9,12 +9,13 @@ However, this protection does not apply when using [`innerHTML`](/reference/jsx- To protect your application from XSS attacks: +- Set a [Content Security Policy (CSP)](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP). +- Validate and sanitize user inputs, especially form inputs on the server and client. - Avoid using `innerHTML` when possible. If necessary, make sure to sanitize user-supplied data with libraries such as [DOMPurify](https://github.com/cure53/DOMPurify). -- Validate and sanitize user inputs, especially form inputs on the server and client. -- Set a [Content Security Policy (CSP)](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP). - Sanitize attributes containing user-supplied data within `