Skip to main content
JAVASCRIPT-BASICS5 MIN READ

Render user text without creating an XSS hole

Render untrusted user text safely by using text sinks instead of HTML sinks.

Render a user comment preview without letting the comment string become executable HTML. Untrusted text goes to text sinks; only trusted or sanitized markup goes to HTML sinks. The common trap is using innerHTML because it is convenient for templates. With untrusted input, that convenience changes the browser's job from displaying text to parsing markup. Before preview.innerHTML = commentText; a pasted tag is parsed as HTML. After preview.textContent = commentText; the exact characters are displayed as text. Identify the source Mark commentText as untrusted because it comes from a user-controlled field. Security starts by knowing whether the string is data…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us