Safe DOM and linting battlecards
Recall safer responses to common beginner shortcuts around DOM insertion and undeclared variables.
Untrusted text Using innerHTML is faster for this user comment preview. The string comes from a textarea and does not need HTML formatting. Your line Because this is user text, not trusted markup, use textContent. It displays the same characters without asking the browser to parse them as HTML. Speed of writing is not the same as safety of rendering. It applies OWASP's safe-sink principle in plain JavaScript. Globals Undeclared assignment vs declared state The linter's no-undef warning is a design clue, not just a syntax complaint. Linting The app runs, so the no-undef warning is just noise. A variable…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in