3 ms·
Yup, innerHTML just returns a string, so of course you can .toUpperCase() on it even if it is unsafe. innerHTML's history is fascinating. It was not part of th
by mediumdeviation 5y ago
Yup, innerHTML just returns a string, so of course you can .toUpperCase() on it even if it is unsafe.
innerHTML's history is fascinating. It was not part of the original DOM Level 1 API but was added in IE5. It is not semantically correct (you should be using Element.textContent or examining the inner text nodes), but because it was so easy and the rest of the DOM API so verbose, it caught on and became one of the primary ways used to manipulate content in JS.
FWIW Chrome recently proposed a Trusted Type mechanism for preventing XSS (which also has the side effect of blocking this sort of unsafe manipulation) - https://web.dev/trusted-types/ https://web.dev/trusted-types/, https://developer.mozilla.org/en-US/docs/Web/API/TrustedHTML https://developer.mozilla.org/en-US/docs/Web/API/TrustedHTML