User content written as markup ============================== Rule · bucket: mechanical · severity: warning · detector: interface-safety · since: v0.14.0 Section: Things to avoid Group: Safety at the interface Forbidden: `dangerouslySetInnerHTML`, `v-html`, `innerHTML =`, `{@html}` carrying anything a person typed Instead: Render it as text. Where formatting is genuinely required, sanitise on the way in with a library that is maintained, and keep the allowed set to what the feature needs. The name of the React prop is a warning someone wrote on purpose. A comment, a display name, a product description: each is a place a script arrives and runs with your origin's privileges.