4 ms·
Of course you can still do <div> + input + </div> in CSR, but you can definitely not do myelement.textContent = whateverIGot in SSR, right?
by furstenheim 5y ago
Of course you can still do <div> + input + </div> in CSR, but you can definitely not do myelement.textContent = whateverIGot in SSR, right?
- asddubs 5y agoyou can use a template engine that escapes all variables by default. in either case, it's just about coding defensively and being secure by default
- furstenheim 5y agoThen why is parameter query safer? And not just escapes variables? Escaping is hard, as shown in the article
- asddubs 5y agogenerating html using find and replace/regex safely is hard. escaping is easy. and the solution is to just not generate html using find and replace. You'll run into the exact same problem trying to do a bbcode/markdown/whatever parser using javascript