[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"verticals":3,"playground-html-sanitizer-api-native-xss-defense":44,"search-suggestions":58},[4,20,32],{"id":5,"slug":6,"name":7,"tagline":8,"description":9,"accentFrom":10,"accentTo":11,"icon":12,"defaultLocale":13,"locales":14,"features":16,"position":19},"019fe637-3d33-714b-b57f-23e163ffca0c","dev","Web Development","Read it. Run it. Prove it.","A post a day on modern web development — most with an editable playground and a quiz that explains every answer. Free, no account needed.","violet-500","cyan-400","◇","en",[13,15],"fa",{"courses":17,"paths":17,"articles":17,"exams":18,"flashcards":18,"packages":17,"community":17,"certificates":17,"teams":17,"commerce":17},true,false,0,{"id":21,"slug":22,"name":23,"tagline":24,"description":25,"accentFrom":26,"accentTo":10,"icon":27,"defaultLocale":13,"locales":28,"features":30,"position":31},"019fe637-3dc2-754c-8657-0f175bfee7c6","lang","Languages","Learn a language the way you learn a codebase.","Grammar explained the way good documentation explains an API — one idea at a time, each with a quiz.","amber-400","⌘",[13,15,29],"es",{"courses":18,"paths":18,"articles":17,"exams":18,"flashcards":17,"packages":18,"community":17,"certificates":17,"teams":18,"commerce":18},2,{"id":33,"slug":34,"name":35,"tagline":36,"description":37,"accentFrom":38,"accentTo":39,"icon":40,"defaultLocale":13,"locales":41,"features":42,"position":43},"7b3c16f2-931d-410e-802e-e1fa4edab7de","soft","Soft Skills","The half of the job nobody wrote documentation for.","Weekly, on the parts of working life that decide more than your code does — first weeks, meetings, interviews, promotions, and the people around you. Written from what actually happens, and recorded as a podcast you can listen to on the walk.","emerald-400","teal-300","◉",[13],{"courses":18,"paths":18,"articles":17,"exams":18,"flashcards":18,"packages":18,"community":17,"certificates":18,"teams":18,"commerce":18},3,{"slug":45,"title":46,"summary":47,"html":48,"css":49,"js":50,"config":51,"doc":53},"html-sanitizer-api-native-xss-defense","setHTML() vs innerHTML — interactive playground",null,"\u003Cdiv class=\"pg\">\n    \u003Ch1 class=\"pg-title\">🎮 Watch the payload actually run — or not\u003C\u002Fh1>\n    \u003Cp class=\"pg-sub\">\n      Pick a payload, choose how it gets inserted, then render it for real. The\n      \u003Ccode>innerHTML\u003C\u002Fcode> and \u003Ccode>setHTMLUnsafe()\u003C\u002Fcode> modes really do\n      insert the string. If something fires, the browser actually ran it; it's\n      not an animation.\n    \u003C\u002Fp>\n\n    \u003Cdiv class=\"banner\" id=\"supportBanner\">\u003C\u002Fdiv>\n\n    \u003Cdiv class=\"panel\">\n      \u003Cdiv class=\"panel-label\">\u003Cspan class=\"n\">1\u003C\u002Fspan> Pick a payload (or type your own)\u003C\u002Fdiv>\n      \u003Cdiv class=\"presets\">\n        \u003Cbutton class=\"btn sm\" data-preset=\"safe\">Safe comment\u003C\u002Fbutton>\n        \u003Cbutton class=\"btn sm\" data-preset=\"script\">&lt;script&gt; tag\u003C\u002Fbutton>\n        \u003Cbutton class=\"btn sm\" data-preset=\"img\">&lt;img onerror&gt;\u003C\u002Fbutton>\n        \u003Cbutton class=\"btn sm\" data-preset=\"jsurl\">javascript: link\u003C\u002Fbutton>\n        \u003Cbutton class=\"btn sm\" data-preset=\"rich\">Rich formatting\u003C\u002Fbutton>\n      \u003C\u002Fdiv>\n      \u003Ctextarea id=\"htmlInput\" style=\"margin-top:10px\" rows=\"4\" spellcheck=\"false\" aria-label=\"HTML to insert\">\u003C\u002Ftextarea>\n\n      \u003Cdiv class=\"row-label\">How the string gets inserted\u003C\u002Fdiv>\n      \u003Cdiv class=\"seg\" id=\"modeSeg\">\n        \u003Cbutton aria-pressed=\"true\" data-mode=\"inner\">innerHTML (unsafe)\u003C\u002Fbutton>\n        \u003Cbutton aria-pressed=\"false\" data-mode=\"unsafe\" id=\"unsafeBtn\">setHTMLUnsafe() (unsafe)\u003C\u002Fbutton>\n        \u003Cbutton aria-pressed=\"false\" data-mode=\"safe\">setHTML() (sanitized)\u003C\u002Fbutton>\n      \u003C\u002Fdiv>\n\n      \u003Cdiv id=\"configRow\" hidden>\n        \u003Cdiv class=\"row-label\">Which sanitizer config \u003Ccode>setHTML()\u003C\u002Fcode> gets\u003C\u002Fdiv>\n        \u003Cdiv class=\"seg\" id=\"configSeg\">\n          \u003Cbutton aria-pressed=\"true\" data-config=\"default\">default (no config)\u003C\u002Fbutton>\n          \u003Cbutton aria-pressed=\"false\" data-config=\"custom\">custom allowlist\u003C\u002Fbutton>\n          \u003Cbutton aria-pressed=\"false\" data-config=\"legacy\">same allowlist, 2022 key names\u003C\u002Fbutton>\n        \u003C\u002Fdiv>\n      \u003C\u002Fdiv>\n\n      \u003Cdiv class=\"panel-label\" style=\"margin-top:14px\">\u003Cspan class=\"n\">·\u003C\u002Fspan> The call that runs\u003C\u002Fdiv>\n      \u003Cpre class=\"code\" id=\"callOut\">—\u003C\u002Fpre>\n\n      \u003Cdiv class=\"btn-row\" style=\"margin-top:14px\">\n        \u003Cbutton class=\"btn primary\" id=\"run\">Render\u003C\u002Fbutton>\n        \u003Cbutton class=\"btn ghost\" id=\"reset\">Reset\u003C\u002Fbutton>\n      \u003C\u002Fdiv>\n    \u003C\u002Fdiv>\n\n    \u003Cdiv class=\"panel\">\n      \u003Cdiv class=\"panel-label\">\u003Cspan class=\"n\">2\u003C\u002Fspan> What actually rendered\u003C\u002Fdiv>\n      \u003Cdiv class=\"stage\" id=\"stage\">—\u003C\u002Fdiv>\n      \u003Cdiv class=\"status\" id=\"status\" style=\"margin-top:12px\">\n        \u003Cspan class=\"dot info\" id=\"dot\">\u003C\u002Fspan>\u003Cspan id=\"statusText\">Pick a payload above and hit Render.\u003C\u002Fspan>\n      \u003C\u002Fdiv>\n      \u003Cp class=\"hint\" id=\"removedOut\">\u003C\u002Fp>\n\n      \u003Cdiv class=\"panel-label\" style=\"margin-top:14px\">\u003Cspan class=\"n\">·\u003C\u002Fspan> DOM after render\u003C\u002Fdiv>\n      \u003Cpre class=\"code\" id=\"codeOut\">—\u003C\u002Fpre>\n\n      \u003Cdiv id=\"getBlock\" hidden>\n        \u003Cdiv class=\"panel-label\" style=\"margin-top:14px\">\u003Cspan class=\"n\">·\u003C\u002Fspan> \u003Cspan id=\"getLabel\">sanitizer.get(): what the browser actually understood\u003C\u002Fspan>\u003C\u002Fdiv>\n        \u003Cpre class=\"code\" id=\"getOut\">—\u003C\u002Fpre>\n      \u003C\u002Fdiv>\n    \u003C\u002Fdiv>\n  \u003C\u002Fdiv>","\u002F*\n * Shared playground design system — daily-post\n * ============================================\n * Link it from any post's playground\u002Findex.html (no per-post boilerplate):\n *\n *   \u003Clink rel=\"stylesheet\" href=\"..\u002F..\u002F..\u002Fplayground\u002Fassets\u002Fbase.css\" \u002F>\n *\n * The relative path resolves the same locally (posts\u002F\u003Cbase>\u002Fplayground\u002F) and on\n * the deployed host (public\u002Fposts\u002F\u003Cbase>\u002Fplayground\u002F), because build-site.js\n * mirrors this file to public\u002Fplayground\u002Fassets\u002Fbase.css. For a CodeSandbox\n * --embed, playground.js inlines this file so the single-file sandbox still styles.\n *\n * Then write ONLY the demo-specific CSS in your inline \u003Cstyle>. Everything below\n * — tokens, layout, panels, buttons, toggles, sliders, code blocks, status\u002Flog,\n * banners, presets — comes for free and looks consistent across every post.\n *\n * Theme-aware: dark by default, light via prefers-color-scheme AND a\n * [data-theme] override on \u003Chtml> (so a toggle can force either). Accessible:\n * real focus rings, adequate contrast, reduced-motion honored.\n *\u002F\n\n\u002F* ---------- design tokens ---------- *\u002F\n:root {\n  --bg: #0d1117;\n  --bg-grid: #ffffff0a;\n  --panel: #161b22;\n  --panel-2: #0b0e14;\n  --card: #0b0e14;\n  --ink: #e8ebf2;\n  --muted: #9aa4b2;\n  --faint: #6b7688;\n  --line: #232a35;\n  --line-soft: #ffffff12;\n  --accent: #7c9cff;\n  --accent-ink: #0b0e14;\n  --good: #3fb950;\n  --warn: #f0883e;\n  --bad: #f85149;\n  --info: #58a6ff;\n  --radius: 14px;\n  --radius-sm: 9px;\n  --shadow: 0 8px 30px #0006;\n  --shadow-sm: 0 4px 14px #0005;\n  --mono: ui-monospace, SFMono-Regular, \"SF Mono\", Menlo, Consolas, \"Liberation Mono\", monospace;\n  --sans: ui-sans-serif, system-ui, -apple-system, \"Segoe UI\", Roboto, \"Helvetica Neue\", sans-serif;\n  color-scheme: dark;\n}\n\n\u002F* Light theme — system preference, overridable by [data-theme] on \u003Chtml>. *\u002F\n@media (prefers-color-scheme: light) {\n  :root:not([data-theme=\"dark\"]) {\n    --bg: #f4f6fb;\n    --bg-grid: #00000008;\n    --panel: #ffffff;\n    --panel-2: #f0f3f9;\n    --card: #f7f9fc;\n    --ink: #131722;\n    --muted: #5b6472;\n    --faint: #8a93a3;\n    --line: #e2e7f0;\n    --line-soft: #00000010;\n    --accent: #2f6df0;\n    --accent-ink: #ffffff;\n    --good: #1a7f37;\n    --warn: #bc4c00;\n    --bad: #cf222e;\n    --info: #0969da;\n    --shadow: 0 8px 30px #0000001f;\n    --shadow-sm: 0 4px 14px #00000014;\n    color-scheme: light;\n  }\n}\n:root[data-theme=\"light\"] {\n  --bg: #f4f6fb;\n  --bg-grid: #00000008;\n  --panel: #ffffff;\n  --panel-2: #f0f3f9;\n  --card: #f7f9fc;\n  --ink: #131722;\n  --muted: #5b6472;\n  --faint: #8a93a3;\n  --line: #e2e7f0;\n  --line-soft: #00000010;\n  --accent: #2f6df0;\n  --accent-ink: #ffffff;\n  --good: #1a7f37;\n  --warn: #bc4c00;\n  --bad: #cf222e;\n  --info: #0969da;\n  --shadow: 0 8px 30px #0000001f;\n  --shadow-sm: 0 4px 14px #00000014;\n  color-scheme: light;\n}\n\n\u002F* ---------- reset & base ---------- *\u002F\n*, *::before, *::after { box-sizing: border-box; }\n\nbody {\n  margin: 0;\n  min-height: 100vh;\n  font-family: var(--sans);\n  color: var(--ink);\n  background:\n    radial-gradient(circle at 1px 1px, var(--bg-grid) 1px, transparent 0) 0 0 \u002F 24px 24px,\n    var(--bg);\n  display: flex;\n  justify-content: center;\n  align-items: flex-start;\n  padding: clamp(14px, 3vw, 26px);\n  line-height: 1.55;\n  -webkit-font-smoothing: antialiased;\n  text-rendering: optimizeLegibility;\n}\n\n\u002F* The single content column. *\u002F\n.pg {\n  width: 100%;\n  max-width: 860px;\n}\n\n\u002F* ---------- header ---------- *\u002F\n.pg-title {\n  font-size: clamp(1.15rem, 1rem + 1vw, 1.4rem);\n  font-weight: 800;\n  letter-spacing: -0.02em;\n  margin: 0 0 4px;\n  display: flex;\n  align-items: center;\n  gap: 9px;\n}\n.pg-sub {\n  color: var(--muted);\n  font-size: 0.92rem;\n  line-height: 1.5;\n  margin: 0 0 16px;\n  max-width: 66ch;\n}\n.pg-sub strong, .pg-sub b { color: var(--ink); font-weight: 700; }\n.pg-sub code { font-family: var(--mono); background: var(--line-soft); color: var(--accent);\n  padding: 1px 6px; border-radius: 6px; font-size: 0.85em; }\n\n\u002F* ---------- panels ---------- *\u002F\n.panel {\n  background: var(--panel);\n  border: 1px solid var(--line);\n  border-radius: var(--radius);\n  padding: 16px 18px;\n  margin-bottom: 14px;\n  box-shadow: var(--shadow-sm);\n}\n.panel-label {\n  font-size: 0.7rem;\n  text-transform: uppercase;\n  letter-spacing: 0.08em;\n  color: var(--muted);\n  font-weight: 800;\n  margin: 0 0 13px;\n  display: flex;\n  align-items: center;\n  gap: 8px;\n}\n.panel-label .n {\n  display: inline-grid; place-items: center;\n  width: 18px; height: 18px; border-radius: 50%;\n  background: var(--accent); color: var(--accent-ink);\n  font-size: 0.66rem; font-weight: 800;\n}\n\n\u002F* ---------- layout helpers ---------- *\u002F\n.row { display: flex; flex-wrap: wrap; gap: 12px; align-items: center; }\n.row.between { justify-content: space-between; }\n.col { display: flex; flex-direction: column; gap: 10px; }\n.grow { flex: 1 1 0; min-width: 0; }\n.wrap-controls { display: flex; flex-wrap: wrap; gap: 16px 24px; align-items: flex-end; }\n.field { display: flex; flex-direction: column; gap: 7px; min-width: 0; }\n.field > .label, .ctl-label {\n  font-size: 0.7rem; text-transform: uppercase; letter-spacing: 0.04em;\n  color: var(--muted); font-weight: 800;\n}\n\n\u002F* ---------- buttons ---------- *\u002F\n.btn {\n  font: inherit; font-weight: 650; font-size: 0.88rem;\n  cursor: pointer; user-select: none;\n  border: 1px solid var(--line);\n  background: var(--card); color: var(--ink);\n  padding: 9px 15px; border-radius: var(--radius-sm);\n  display: inline-flex; align-items: center; gap: 8px;\n  transition: background .15s ease, border-color .15s ease, transform .05s ease, color .15s ease;\n}\n.btn:hover { background: var(--line-soft); border-color: var(--muted); }\n.btn:active { transform: translateY(1px); }\n.btn:focus-visible { outline: 2px solid var(--accent); outline-offset: 2px; }\n.btn[disabled] { opacity: 0.45; cursor: not-allowed; }\n.btn.primary { background: var(--accent); border-color: var(--accent); color: var(--accent-ink); }\n.btn.primary:hover { filter: brightness(1.08); background: var(--accent); }\n.btn.good { background: var(--good); border-color: var(--good); color: #04140a; }\n.btn.bad  { background: var(--bad);  border-color: var(--bad);  color: #fff; }\n.btn.ghost { background: transparent; }\n.btn.sm { padding: 6px 11px; font-size: 0.82rem; }\n\n.btn-row { display: flex; flex-wrap: wrap; gap: 9px; }\n\n\u002F* Segmented control — a row of buttons where one is active (aria-pressed). *\u002F\n.seg { display: inline-flex; background: var(--card); border: 1px solid var(--line);\n  border-radius: var(--radius-sm); padding: 3px; gap: 3px; }\n.seg button {\n  font: inherit; font-weight: 650; font-size: 0.84rem; cursor: pointer;\n  border: none; background: transparent; color: var(--muted);\n  padding: 7px 13px; border-radius: 7px;\n  transition: background .15s ease, color .15s ease;\n}\n.seg button:hover { color: var(--ink); }\n.seg button[aria-pressed=\"true\"] { background: var(--accent); color: var(--accent-ink); }\n.seg button:focus-visible { outline: 2px solid var(--accent); outline-offset: 2px; }\n\n\u002F* Preset chips — worked-example shortcuts. *\u002F\n.presets { display: flex; flex-wrap: wrap; gap: 8px; }\n.presets .btn { background: var(--panel-2); }\n\n\u002F* ---------- toggle switch ---------- *\u002F\n.toggle { display: inline-flex; align-items: center; gap: 10px; cursor: pointer;\n  font-size: 0.88rem; font-weight: 600; user-select: none; }\n.toggle input { position: absolute; opacity: 0; width: 0; height: 0; }\n.switch { position: relative; width: 44px; height: 25px; border-radius: 999px; flex: none;\n  background: var(--line); border: 1px solid var(--line); transition: background .18s ease; }\n.switch::after { content: \"\"; position: absolute; top: 2px; left: 2px; width: 19px; height: 19px;\n  border-radius: 50%; background: #cfd6e4; transition: transform .18s ease; box-shadow: 0 1px 3px #0006; }\n.toggle input:checked + .switch { background: var(--good); border-color: var(--good); }\n.toggle input:checked + .switch::after { transform: translateX(19px); background: #fff; }\n.toggle input:focus-visible + .switch { outline: 2px solid var(--accent); outline-offset: 2px; }\n\n\u002F* ---------- range slider ---------- *\u002F\ninput[type=\"range\"] {\n  -webkit-appearance: none; appearance: none; width: 100%; height: 6px;\n  background: var(--line); border-radius: 999px; outline: none; cursor: pointer; margin: 8px 0;\n}\ninput[type=\"range\"]::-webkit-slider-thumb {\n  -webkit-appearance: none; appearance: none; width: 19px; height: 19px; border-radius: 50%;\n  background: var(--accent); border: 2px solid var(--panel); box-shadow: var(--shadow-sm); cursor: pointer;\n}\ninput[type=\"range\"]::-moz-range-thumb {\n  width: 19px; height: 19px; border-radius: 50%; background: var(--accent);\n  border: 2px solid var(--panel); box-shadow: var(--shadow-sm); cursor: pointer;\n}\ninput[type=\"range\"]:focus-visible { outline: 2px solid var(--accent); outline-offset: 3px; }\n\n\u002F* ---------- text inputs \u002F selects ---------- *\u002F\ninput[type=\"text\"], input[type=\"number\"], input[type=\"search\"], select, textarea {\n  font: inherit; color: var(--ink); background: var(--card);\n  border: 1px solid var(--line); border-radius: var(--radius-sm); padding: 8px 11px; width: 100%;\n}\ntextarea { font-family: var(--mono); font-size: 0.85rem; line-height: 1.6; resize: vertical; }\ninput:focus-visible, select:focus-visible, textarea:focus-visible {\n  outline: 2px solid var(--accent); outline-offset: 1px; border-color: var(--accent);\n}\n\n\u002F* ---------- status \u002F output \u002F log ---------- *\u002F\n.status {\n  display: flex; align-items: center; gap: 9px; flex-wrap: wrap;\n  font-size: 0.9rem; font-weight: 600;\n  padding: 11px 14px; border-radius: var(--radius-sm);\n  background: var(--panel-2); border: 1px solid var(--line); color: var(--ink);\n}\n.status.good { border-color: color-mix(in srgb, var(--good) 55%, var(--line)); }\n.status.warn { border-color: color-mix(in srgb, var(--warn) 55%, var(--line)); }\n.status.bad  { border-color: color-mix(in srgb, var(--bad) 55%, var(--line)); }\n.dot { width: 9px; height: 9px; border-radius: 50%; background: var(--muted); flex: none; }\n.dot.good { background: var(--good); } .dot.warn { background: var(--warn); }\n.dot.bad { background: var(--bad); } .dot.info { background: var(--info); }\n\n.output { background: var(--panel-2); border: 1px solid var(--line); border-radius: var(--radius-sm);\n  padding: 13px 15px; }\n.log { font-family: var(--mono); font-size: 0.8rem; line-height: 1.7; background: var(--card);\n  border: 1px solid var(--line); border-radius: var(--radius-sm); padding: 11px 14px;\n  max-height: 220px; overflow-y: auto; white-space: pre-wrap; }\n\n\u002F* ---------- code block + syntax tokens ---------- *\u002F\n.code {\n  font-family: var(--mono); font-size: 0.82rem; line-height: 1.7;\n  background: var(--panel-2); border: 1px solid var(--line); border-radius: var(--radius-sm);\n  padding: 13px 15px; overflow-x: auto; white-space: pre; tab-size: 2;\n}\n.code .tok-sel  { color: var(--accent); }\n.code .tok-prop { color: #86e29b; }\n.code .tok-kw   { color: #ff9bcb; }\n.code .tok-str  { color: #f0c674; }\n.code .tok-num  { color: #f0883e; }\n.code .tok-cmt  { color: var(--faint); font-style: italic; }\n.code .hl { background: color-mix(in srgb, var(--good) 22%, transparent); border-radius: 4px; padding: 0 3px; }\n\n\u002F* ---------- hint \u002F caption ---------- *\u002F\n.hint { font-size: 0.83rem; color: var(--muted); line-height: 1.55; margin: 10px 0 0; }\n.hint code { font-family: var(--mono); color: var(--ink); background: var(--line-soft);\n  padding: 1px 5px; border-radius: 5px; font-size: 0.86em; }\n.hint strong { color: var(--ink); }\n\n\u002F* ---------- banner (feature-support \u002F notices) ---------- *\u002F\n.banner {\n  display: none; margin-bottom: 14px; padding: 11px 14px; border-radius: 11px;\n  font-size: 0.85rem; line-height: 1.5;\n  color: var(--ink); background: color-mix(in srgb, var(--warn) 12%, var(--panel));\n  border: 1px solid color-mix(in srgb, var(--warn) 45%, var(--line));\n}\n.banner.show { display: block; }\n.banner.info { background: color-mix(in srgb, var(--info) 12%, var(--panel));\n  border-color: color-mix(in srgb, var(--info) 45%, var(--line)); }\n.banner code { font-family: var(--mono); background: var(--line-soft); padding: 1px 5px; border-radius: 5px; }\n\n\u002F* ---------- misc atoms ---------- *\u002F\n.pill { display: inline-flex; align-items: center; gap: 6px; font-size: 0.75rem; font-weight: 700;\n  padding: 3px 9px; border-radius: 999px; background: var(--line-soft); color: var(--muted); }\n.pill.good { color: var(--good); background: color-mix(in srgb, var(--good) 16%, transparent); }\n.pill.bad  { color: var(--bad);  background: color-mix(in srgb, var(--bad) 16%, transparent); }\n.mono { font-family: var(--mono); }\n.muted { color: var(--muted); }\n.big-num { font-family: var(--mono); font-size: 1.6rem; font-weight: 800; letter-spacing: -0.02em; }\n\n\u002F* Optional theme toggle button (top-right). Wire it in JS if you want it. *\u002F\n.theme-btn { position: fixed; top: 12px; right: 12px; z-index: 20; }\n\n\u002F* ---------- responsive ---------- *\u002F\n@media (max-width: 560px) {\n  .panel { padding: 14px; }\n  .wrap-controls { gap: 14px; }\n  .btn { padding: 9px 13px; }\n}\n\n\u002F* ---------- reduced motion ---------- *\u002F\n@media (prefers-reduced-motion: reduce) {\n  *, *::before, *::after { transition-duration: 0.01ms !important; animation-duration: 0.01ms !important; }\n}\n\n\ntextarea#htmlInput {\n    width: 100%; box-sizing: border-box; min-height: 96px; resize: vertical;\n    padding: 10px 12px; border-radius: var(--radius-sm); border: 1px solid var(--line);\n    background: var(--panel-2); color: inherit; font: 13px\u002F1.5 var(--mono, monospace);\n  }\n  .stage {\n    min-height: 70px; padding: 14px; border: 1px dashed var(--line); border-radius: var(--radius-sm);\n    background: var(--panel-2); word-break: break-word;\n  }\n  .stage img { max-width: 60px; vertical-align: middle; }\n  .row-label { font-size: 0.8rem; color: var(--muted); margin: 14px 0 6px; }\n  .seg { flex-wrap: wrap; }\n  .seg button[disabled] { opacity: 0.45; cursor: not-allowed; }\n  pre.code { white-space: pre-wrap; word-break: break-word; }","\"use strict\";\n  const $ = (id) => document.getElementById(id);\n\n  \u002F\u002F The current API has Sanitizer.prototype.get(); Chrome 105–118's removed 2022 version didn't.\n  const NATIVE =\n    \"setHTML\" in Element.prototype &&\n    typeof window.Sanitizer === \"function\" &&\n    typeof window.Sanitizer.prototype.get === \"function\";\n  const HAS_UNSAFE = \"setHTMLUnsafe\" in Element.prototype;\n\n  const PRESETS = {\n    safe: 'Great post! \u003Cb>Thanks\u003C\u002Fb> for writing this — check out \u003Ca href=\"https:\u002F\u002Fexample.com\">this link\u003C\u002Fa>.',\n    script: '\u003Cp>Cool trick, watch this:\u003C\u002Fp>\\n\u003Cscript>pgUnsafeFire(\\'\u003Cscript> tag\\')\u003C' + '\u002Fscript>',\n    img: '\u003Cp>Nice picture:\u003C\u002Fp>\\n\u003Cimg src=\"x\" onerror=\"pgUnsafeFire(\\'img onerror attribute\\')\">',\n    jsurl: '\u003Cp>You won a prize! \u003Ca href=\"javascript:pgUnsafeFire(\\'javascript: link\\')\">Claim it\u003C\u002Fa>\u003C\u002Fp>',\n    rich:\n      '\u003C!-- internal note -->\\n\u003Ch2 class=\"title\" id=\"notes\">Release notes\u003C\u002Fh2>\\n' +\n      '\u003Cp style=\"color:crimson\" data-ticket=\"42\">Fixed \u003Cspan>the flaky\u003C\u002Fspan> \u003Cb>login\u003C\u002Fb> bug. ' +\n      '\u003Ca href=\"https:\u002F\u002Fexample.com\" target=\"_blank\">Details\u003C\u002Fa>\u003C\u002Fp>\\n\u003Cimg src=\"x\" alt=\"screenshot\">',\n  };\n\n  \u002F\u002F The two custom configs. Same intent; only the key names differ.\n  const CUSTOM = {\n    elements: [\"p\", \"b\", \"i\", \"em\", \"strong\", { name: \"a\", attributes: [\"href\"] }, \"br\"],\n    attributes: [],\n    comments: false,\n    dataAttributes: false,\n  };\n  const LEGACY = {\n    allowElements: [\"p\", \"b\", \"i\", \"em\", \"strong\", \"a\", \"br\"],\n    allowAttributes: { href: [\"a\"] },\n  };\n  const INTENDED_TAGS = new Set([\"p\", \"b\", \"i\", \"em\", \"strong\", \"a\", \"br\"]);\n\n  const CALLS = {\n    inner: \"stage.innerHTML = input;\",\n    unsafe: \"stage.setHTMLUnsafe(input); \u002F\u002F no sanitizer passed\",\n    default: \"stage.setHTML(input); \u002F\u002F built-in default config\",\n    custom:\n      \"const sanitizer = new Sanitizer({\\n\" +\n      '  elements: [\"p\", \"b\", \"i\", \"em\", \"strong\", { name: \"a\", attributes: [\"href\"] }, \"br\"],\\n' +\n      \"  attributes: [],\\n  comments: false,\\n  dataAttributes: false,\\n});\\n\" +\n      \"stage.setHTML(input, { sanitizer });\",\n    legacy:\n      \"\u002F\u002F 2022 draft key names: current browsers silently ignore them\\n\" +\n      \"const sanitizer = new Sanitizer({\\n\" +\n      '  allowElements: [\"p\", \"b\", \"i\", \"em\", \"strong\", \"a\", \"br\"],\\n' +\n      '  allowAttributes: { href: [\"a\"] },\\n});\\n' +\n      \"stage.setHTML(input, { sanitizer });\",\n  };\n\n  \u002F\u002F ---------------------------------------------------------------------------\n  \u002F\u002F FALLBACK MODEL — used ONLY when this browser has no native setHTML().\n  \u002F\u002F A simplified imitation of the spec's rules, written for this page. It is\n  \u002F\u002F not the real API: HTML elements only (SVG\u002FMathML are simply dropped), and\n  \u002F\u002F the always-removed list is the one in the post.\n  \u002F\u002F ---------------------------------------------------------------------------\n  const HTML_NS = \"http:\u002F\u002Fwww.w3.org\u002F1999\u002Fxhtml\";\n  const MODEL_ALWAYS_REMOVED = new Set([\"script\", \"iframe\", \"frame\", \"embed\", \"object\", \"base\"]);\n  const MODEL_NAV_URL_ATTRS = { a: [\"href\"], area: [\"href\"], form: [\"action\"], button: [\"formaction\"], input: [\"formaction\"] };\n  const MODEL_DEFAULT_ELEMENTS = {\n    a: [\"href\", \"hreflang\", \"type\"], abbr: [], address: [], article: [], aside: [], b: [], bdi: [], bdo: [],\n    blockquote: [\"cite\"], body: [], br: [], caption: [], cite: [], code: [], col: [\"span\"], colgroup: [\"span\"],\n    data: [\"value\"], dd: [], del: [\"cite\", \"datetime\"], dfn: [], div: [], dl: [], dt: [], em: [], figcaption: [],\n    figure: [], footer: [], h1: [], h2: [], h3: [], h4: [], h5: [], h6: [], head: [], header: [], hgroup: [],\n    hr: [], html: [], i: [], ins: [\"cite\", \"datetime\"], kbd: [], li: [\"value\"], main: [], mark: [], menu: [],\n    nav: [], ol: [\"reversed\", \"start\", \"type\"], p: [], pre: [], q: [], rp: [], rt: [], ruby: [], s: [], samp: [],\n    search: [], section: [], small: [], span: [], strong: [], sub: [], sup: [], table: [], tbody: [],\n    td: [\"colspan\", \"headers\", \"rowspan\"], tfoot: [], th: [\"abbr\", \"colspan\", \"headers\", \"rowspan\", \"scope\"],\n    thead: [], time: [\"datetime\"], title: [], tr: [], u: [], ul: [], var: [], wbr: [],\n  };\n  const MODEL_DEFAULT_GLOBAL = [\n    \"dir\", \"lang\", \"title\", \"alignment-baseline\", \"baseline-shift\", \"clip-path\", \"clip-rule\", \"color\",\n    \"color-interpolation\", \"cursor\", \"direction\", \"display\", \"displaystyle\", \"dominant-baseline\", \"fill\",\n    \"fill-opacity\", \"fill-rule\", \"font-family\", \"font-size\", \"font-size-adjust\", \"font-stretch\", \"font-style\",\n    \"font-variant\", \"font-weight\", \"letter-spacing\", \"marker-end\", \"marker-mid\", \"marker-start\",\n    \"mathbackground\", \"mathcolor\", \"mathsize\", \"opacity\", \"paint-order\", \"pointer-events\", \"scriptlevel\",\n    \"shape-rendering\", \"stop-color\", \"stop-opacity\", \"stroke\", \"stroke-dasharray\", \"stroke-dashoffset\",\n    \"stroke-linecap\", \"stroke-linejoin\", \"stroke-miterlimit\", \"stroke-opacity\", \"stroke-width\", \"text-anchor\",\n    \"text-decoration\", \"text-overflow\", \"text-rendering\", \"transform\", \"transform-origin\", \"unicode-bidi\",\n    \"vector-effect\", \"visibility\", \"white-space\", \"word-spacing\", \"writing-mode\",\n  ];\n  const MODEL_CONFIGS = {\n    default: { elements: MODEL_DEFAULT_ELEMENTS, globalAttrs: new Set(MODEL_DEFAULT_GLOBAL), comments: false, dataAttributes: false },\n    custom: { elements: { p: [], b: [], i: [], em: [], strong: [], a: [\"href\"], br: [] }, globalAttrs: new Set(), comments: false, dataAttributes: false },\n    \u002F\u002F Unknown keys are ignored, so the 2022 config canonicalizes to \"remove nothing\"\n    \u002F\u002F (and new Sanitizer() defaults comments to true).\n    legacy: { elements: null, globalAttrs: null, comments: true, dataAttributes: true },\n  };\n  const MODEL_DESCRIPTIONS = {\n    default: \"elements: 75 HTML names in this model (no img, style, form, details, template…)\\nattributes: dir, lang, title + SVG\u002FMathML presentation attributes\\ncomments: false\\ndataAttributes: false\",\n    custom: \"elements: a[href], b, br, em, i, p, strong\\nattributes: (none)\\ncomments: false\\ndataAttributes: false\",\n    legacy: \"removeElements: [] (empty: removes nothing extra)\\nremoveAttributes: [] (empty)\\ncomments: true\\n\u002F\u002F allowElements \u002F allowAttributes were ignored\",\n  };\n\n  function isJavascriptURL(value) {\n    try { return new URL(value).protocol === \"javascript:\"; } catch { return false; }\n  }\n\n  function modelSanitize(root, cfg) {\n    for (const child of [...root.childNodes]) {\n      if (child.nodeType === Node.COMMENT_NODE) { if (!cfg.comments) child.remove(); continue; }\n      if (child.nodeType !== Node.ELEMENT_NODE) continue;\n      const name = child.localName;\n      if (child.namespaceURI !== HTML_NS || MODEL_ALWAYS_REMOVED.has(name)) { child.remove(); continue; }\n      let local = [];\n      if (cfg.elements) {\n        if (!Object.prototype.hasOwnProperty.call(cfg.elements, name)) { child.remove(); continue; }\n        local = cfg.elements[name];\n      }\n      for (const attr of [...child.attributes]) {\n        const n = attr.name;\n        let keep = cfg.elements\n          ? cfg.globalAttrs.has(n) || local.includes(n) || (cfg.dataAttributes && n.startsWith(\"data-\"))\n          : true;\n        if (\u002F^on\u002Fi.test(n)) keep = false;\n        if (keep && (MODEL_NAV_URL_ATTRS[name] || []).includes(n) && isJavascriptURL(attr.value)) keep = false;\n        if (!keep) child.removeAttribute(n);\n      }\n      if (name === \"template\") modelSanitize(child.content, cfg);\n      modelSanitize(child, cfg);\n    }\n  }\n\n  function modelSetHTML(target, html, configKey) {\n    \u002F\u002F A \u003Ctemplate> parses into an inert document: nothing loads, nothing runs.\n    const t = document.createElement(\"template\");\n    t.innerHTML = html;\n    modelSanitize(t.content, MODEL_CONFIGS[configKey]);\n    target.replaceChildren(document.importNode(t.content, true));\n  }\n\n  \u002F\u002F --- inventory: what was in the input vs what survived -----------------------\n  function inventory(root) {\n    const els = {}, attrs = {};\n    let comments = 0;\n    const walk = (node) => {\n      for (const c of node.childNodes) {\n        if (c.nodeType === Node.COMMENT_NODE) comments++;\n        else if (c.nodeType === Node.ELEMENT_NODE) {\n          els[c.localName] = (els[c.localName] || 0) + 1;\n          for (const a of c.attributes) {\n            const key = c.localName + \" \" + a.name;\n            attrs[key] = (attrs[key] || 0) + 1;\n          }\n          walk(c.localName === \"template\" ? c.content : c);\n        }\n      }\n    };\n    walk(root);\n    return { els, attrs, comments };\n  }\n  function inputInventory(html) {\n    const t = document.createElement(\"template\");\n    t.innerHTML = html;\n    return inventory(t.content);\n  }\n  \u002F\u002F Attributes are only reported for elements that survived; an element removed\n  \u002F\u002F wholesale is reported once, as the element.\n  function removedSummary(before, after) {\n    const els = [], attrs = new Set();\n    for (const [tag, n] of Object.entries(before.els)) {\n      if ((after.els[tag] || 0) \u003C n) els.push(\"\u003C\" + tag + \">\");\n    }\n    for (const [key, n] of Object.entries(before.attrs)) {\n      const [tag, attr] = key.split(\" \");\n      if ((after.els[tag] || 0) > 0 && (after.attrs[key] || 0) \u003C n) attrs.add(attr);\n    }\n    const parts = [];\n    if (els.length) parts.push(\"elements (with everything inside them): \" + els.join(\" \"));\n    if (attrs.size) parts.push(\"attributes: \" + [...attrs].join(\", \"));\n    if (after.comments \u003C before.comments) parts.push(\"comments\");\n    return parts.length ? \"Removed on the way in: \" + parts.join(\" · \") : \"Nothing was removed on the way in.\";\n  }\n\n  function describeConfig(cfg) {\n    return Object.keys(cfg).sort().map((key) => {\n      const v = cfg[key];\n      if (!Array.isArray(v)) return key + \": \" + JSON.stringify(v);\n      if (v.length === 0) return key + \": [] (empty)\";\n      const names = v.map((item) => {\n        if (typeof item === \"string\") return item;\n        const a = (item.attributes || []).map((x) => x.name);\n        return item.name + (a.length ? \"[\" + a.join(\",\") + \"]\" : \"\");\n      });\n      const shown = names.length > 14 ? names.slice(0, 14).join(\", \") + \", … (\" + names.length + \" total)\" : names.join(\", \");\n      return key + \": \" + shown;\n    }).join(\"\\n\");\n  }\n\n  \u002F\u002F --- state + UI --------------------------------------------------------------\n  let mode = \"inner\";\n  let config = \"default\";\n  let fired = false;\n  let lastRunId = 0;\n\n  window.pgUnsafeFire = function (source) {\n    fired = true;\n    setStatus(\"🔴 Unsafe code ran: the \" + source + \" payload executed.\", \"bad\");\n  };\n\n  function setStatus(text, kind) {\n    $(\"statusText\").textContent = text;\n    $(\"dot\").className = \"dot \" + kind;\n  }\n\n  function callKey() { return mode === \"safe\" ? config : mode; }\n  function refreshCall() {\n    let text = CALLS[callKey()];\n    if (mode === \"safe\" && !NATIVE) text = \"\u002F\u002F MODEL: your browser has no setHTML(), so this page imitates:\\n\" + text;\n    $(\"callOut\").textContent = text;\n    $(\"configRow\").hidden = mode !== \"safe\";\n  }\n\n  function setupSupport() {\n    const b = $(\"supportBanner\");\n    if (NATIVE) {\n      b.className = \"banner info show\";\n      b.innerHTML = \"✅ Your browser has the real \u003Ccode>setHTML()\u003C\u002Fcode> and \u003Ccode>Sanitizer\u003C\u002Fcode>. The sanitized mode below calls them for real.\";\n    } else {\n      b.className = \"banner show\";\n      b.innerHTML =\n        \"⚠️ Your browser doesn't have \u003Ccode>setHTML()\u003C\u002Fcode> yet (Safari hasn't shipped it as of this writing). \" +\n        \"The \u003Ccode>setHTML()\u003C\u002Fcode> mode below therefore runs a \u003Cstrong>model\u003C\u002Fstrong>: a simplified JavaScript imitation \" +\n        \"of the spec's rules, written for this page. It covers HTML elements only (SVG and MathML are simply dropped), \" +\n        \"so treat its output as an illustration. Open this page in Firefox 148+ or Chrome 146+ to see the real thing.\";\n    }\n    if (!HAS_UNSAFE) {\n      const u = $(\"unsafeBtn\");\n      u.disabled = true;\n      u.title = \"This browser has no setHTMLUnsafe()\";\n      u.textContent = \"setHTMLUnsafe() (not in this browser)\";\n    }\n  }\n\n  document.querySelectorAll(\"[data-preset]\").forEach((btn) => {\n    btn.addEventListener(\"click\", () => { $(\"htmlInput\").value = PRESETS[btn.dataset.preset]; });\n  });\n\n  $(\"modeSeg\").addEventListener(\"click\", (e) => {\n    const btn = e.target.closest(\"[data-mode]\");\n    if (!btn || btn.disabled) return;\n    mode = btn.dataset.mode;\n    $(\"modeSeg\").querySelectorAll(\"[data-mode]\").forEach((b) => b.setAttribute(\"aria-pressed\", String(b === btn)));\n    refreshCall();\n  });\n\n  $(\"configSeg\").addEventListener(\"click\", (e) => {\n    const btn = e.target.closest(\"[data-config]\");\n    if (!btn) return;\n    config = btn.dataset.config;\n    $(\"configSeg\").querySelectorAll(\"[data-config]\").forEach((b) => b.setAttribute(\"aria-pressed\", String(b === btn)));\n    refreshCall();\n  });\n\n  $(\"run\").addEventListener(\"click\", () => {\n    const runId = ++lastRunId;\n    fired = false;\n    const html = $(\"htmlInput\").value || \"\";\n    const stage = $(\"stage\");\n    stage.textContent = \"\";\n    $(\"getBlock\").hidden = true;\n    let usedModel = false;\n\n    try {\n      if (mode === \"inner\") {\n        stage.innerHTML = html;\n      } else if (mode === \"unsafe\") {\n        stage.setHTMLUnsafe(html);\n      } else if (NATIVE) {\n        if (config === \"default\") {\n          stage.setHTML(html);\n        } else {\n          const sanitizer = new Sanitizer(config === \"custom\" ? CUSTOM : LEGACY);\n          stage.setHTML(html, { sanitizer });\n          $(\"getLabel\").textContent = \"sanitizer.get(): what the browser actually understood\";\n          $(\"getOut\").textContent = describeConfig(sanitizer.get());\n          $(\"getBlock\").hidden = false;\n        }\n      } else {\n        usedModel = true;\n        modelSetHTML(stage, html, config);\n        $(\"getLabel\").textContent = \"The config this MODEL applies (your browser has no Sanitizer.get())\";\n        $(\"getOut\").textContent = MODEL_DESCRIPTIONS[config];\n        $(\"getBlock\").hidden = false;\n      }\n    } catch (err) {\n      stage.textContent = \"That call threw: \" + err.message;\n    }\n\n    const where = mode === \"inner\" ? \"innerHTML\" : mode === \"unsafe\" ? \"setHTMLUnsafe()\" : usedModel ? \"the setHTML() MODEL\" : \"the real setHTML()\";\n    setStatus(\"Rendered with \" + where + \". Watching for anything that fires…\", \"info\");\n    $(\"codeOut\").textContent = stage.innerHTML || \"(empty)\";\n\n    $(\"removedOut\").textContent = removedSummary(inputInventory(html), inventory(stage));\n\n    setTimeout(() => {\n      if (fired || runId !== lastRunId) return;\n      const hasJsLink = [...stage.querySelectorAll(\"a[href]\")].some((a) => isJavascriptURL(a.getAttribute(\"href\")));\n      const hasScript = !!stage.querySelector(\"script\");\n      if (mode !== \"safe\") {\n        if (hasJsLink) setStatus(\"Nothing fired yet, but the javascript: link survived. Click it in the output above.\", \"warn\");\n        else if (hasScript) setStatus(\"Nothing fired. The \u003Cscript> is right there in the DOM, but scripts inserted this way never run. Try the \u003Cimg onerror> preset.\", \"warn\");\n        else setStatus(\"Nothing fired for this payload with \" + where + \".\", \"warn\");\n        return;\n      }\n      const prefix = usedModel ? \"[model] \" : \"\";\n      if (config === \"legacy\") {\n        const after = inventory(stage);\n        const extra = Object.keys(after.els).filter((t) => !INTENDED_TAGS.has(t)).map((t) => \"\u003C\" + t + \">\")\n          .concat([...new Set(Object.keys(after.attrs).filter((k) => k !== \"a href\").map((k) => k.split(\" \")[1] + \"=\"))])\n          .concat(after.comments ? [\"comments\"] : []);\n        if (extra.length) {\n          setStatus(prefix + \"⚠️ Nothing ran (the always-on removals still happen), but this \\\"strict\\\" config let through: \" +\n            extra.join(\", \") + (usedModel ? \". The model ignores allowElements, as real browsers do.\" : \". The browser ignored allowElements.\"), \"warn\");\n          return;\n        }\n      }\n      setStatus(prefix + \"✅ Sanitized. No script, event handler or javascript: URL survived to run.\", \"good\");\n    }, 600);\n  });\n\n  $(\"reset\").addEventListener(\"click\", () => {\n    lastRunId++;\n    $(\"htmlInput\").value = PRESETS.safe;\n    $(\"stage\").textContent = \"—\";\n    $(\"codeOut\").textContent = \"—\";\n    $(\"removedOut\").textContent = \"\";\n    $(\"getBlock\").hidden = true;\n    setStatus(\"Pick a payload above and hit Render.\", \"info\");\n  });\n\n  setupSupport();\n  $(\"htmlInput\").value = PRESETS.safe;\n  refreshCall();",{"height":52,"autorun":17},520,{"slug":45,"title":54,"excerpt":55,"coverUrl":56,"vertical":57},"Blocking `\u003Cscript>` Won't Stop innerHTML XSS. `setHTML()` Will.","A regex that strips \u003Cscript> tags misses the XSS that actually runs — an onerror attribute. Element.setHTML(), from the HTML Sanitizer API, strips it natively, and for once Firefox shipped the finished version before Chrome did.","\u002Fmedia\u002Fcovers\u002Fhtml-sanitizer-api-native-xss-defense.png",{"slug":6},[59,63,67,71,75,79,83,87,91,95,99,103],{"slug":60,"name":61,"articles":62},"webdev","Webdev",115,{"slug":64,"name":65,"articles":66},"javascript","Javascript",97,{"slug":68,"name":69,"articles":70},"frontend","Frontend",75,{"slug":72,"name":73,"articles":74},"tutorial","Tutorial",41,{"slug":76,"name":77,"articles":78},"css","Css",36,{"slug":80,"name":81,"articles":82},"typescript","Typescript",17,{"slug":84,"name":85,"articles":86},"performance","Performance",14,{"slug":88,"name":89,"articles":90},"react","React",13,{"slug":92,"name":93,"articles":94},"browser","Browser",11,{"slug":96,"name":97,"articles":98},"node","Node",10,{"slug":100,"name":101,"articles":102},"html","Html",8,{"slug":104,"name":105,"articles":106},"accessibility","Accessibility",7]