3 ms·
This is primarily an ergonomic addition, so it kinda makes sense to me to not make the dangerous footguns more ergonomic in the process. You can still assign `i
by strbean 1y ago
This is primarily an ergonomic addition, so it kinda makes sense to me to not make the dangerous footguns more ergonomic in the process. You can still assign `innerHTML` etc. to do the dangerous thing.
- hsbauauvhabzb 1y agoIdeally this should be called dangerouslySetInnerHTML but hindsight blah blah
- meowface 1y agoI agree, though I also agree with the parent that the method name is a little bit confusing. "safeSetHTML" or "setUntrustedHTML" or something would be clearer.
- strbean 1y agoIdk about that, there's a good argument that the most obvious methods should be the safe ones. That's what juniors will probably jump to first. If you need the unsafe ones, you'll probably be able to figure that out and find them quickly.
- jfengel 1y agoI like React's dangerouslySetInnerHTML. The name so clearly conveys "you can do this but you really, really, really shouldn't".
- domenicd 1y agoIndeed, the web platform now has setHTML() and setHTMLUnsafe() to replace the innerHTML setter. There's also getHTML() (which has extra capabilities over the innerHTML getter).
- meowface 1y agoOkay, I've changed my mind and agree this is better, then. I wasn't aware they were adding two new methods. That is the safest way to do it.
- SoftTalker 1y agoWhy not name it what it does: sanitizeAndSetHTML
- xp84 1y agoNaming things in that manner hasn’t proven to be a good idea over the years. When you have 2 of something and one is safe/better and the other one is known to be problematic, you give the awkward name to the problematic one and the obvious name to the safe/better one. Noobs oughtn’t to be attempting the other one, and anyone who is mature enough to have reason to do it, are mature enough to appreciate the reason behind that complexity.
- pwdisswordfishy 1y agoIt doesn't matter when the "unsafe" method is already so entrenched and easy to reach for.
- xp84 1y agoSure it does. A baby developer today has a good chance of discovering setHTML first. The most “with it” keep abreast of great new additions to the DOM API. We just have to educate the mid-levels (and hope the AI that does most of the actual code authoring for the juniors gets the memo quickly).