User content written as markup
- Forbidden
dangerouslySetInnerHTML,v-html,innerHTML =,{@html}carrying anything a person typed- Instead
- Render it as text. Where formatting is genuinely required, sanitise on the way in with a library that is maintained, and keep the allowed set to what the feature needs.
What this rule looks like
Why this rule
The name of the React prop is a warning someone wrote on purpose. A comment, a display name, a product description: each is a place a script arrives and runs with your origin's privileges.
- Kind
- Rule
- Section
- Things to avoid
- Group
- Safety at the interface
- Bucket
- mechanical
- Severity
- warning
- Detector
interface-safety- Since
- v0.14.0