The draft report on a Sanitizer API is now in draft stage. It would let the browser clean user input before it is used again on the page. The draft report says:The browser has a fairly good idea of when it is going to execute code. We can improve upon the user-space libraries by teaching the browser how to render HTML from an arbitrary string in a safe manner.
2 Comments
Sort: