mirror of
https://github.com/sveltejs/svelte.git
synced 2024-12-01 17:30:59 +01:00
clarify when sanitization is done and when not
This commit is contained in:
parent
85b1850b77
commit
1df741a374
@ -12,4 +12,4 @@ In Svelte, you do this with the special `{@html ...}` tag:
|
||||
<p>{@html string}</p>
|
||||
```
|
||||
|
||||
> Svelte doesn't perform any sanitization of the data before it gets inserted into the DOM. In other words, it's critical that you manually escape HTML that comes from sources you don't trust, otherwise you risk exposing your users to XSS attacks.
|
||||
> Svelte doesn't perform any sanitization of the data before it gets inserted into the DOM via a @html-tag. In other words, if you use `{@html ...}` it's critical that you manually escape HTML that comes from sources you don't trust, otherwise you risk exposing your users to XSS attacks.
|
||||
|
Loading…
Reference in New Issue
Block a user