Skip to content
GitHub
Sections

Reference · Things to avoid

User content written as markup

Forbidden
dangerouslySetInnerHTML, v-html, innerHTML =, {@html} carrying anything a person typed
Instead
Render it as text. Where formatting is genuinely required, sanitise on the way in with a library that is maintained, and keep the allowed set to what the feature needs.

What this rule looks like

Forbidden
Instead

Why this rule

The name of the React prop is a warning someone wrote on purpose. A comment, a display name, a product description: each is a place a script arrives and runs with your origin's privileges.

Kind
Rule
Section
Things to avoid
Group
Safety at the interface
Bucket
mechanical
Severity
warning
Detector
interface-safety
Since
v0.14.0

Read as plain text