Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148
Firefox 148 becomes the first browser to ship the standardized Sanitizer API, which lets developers sanitize untrusted HTML before inserting it into the DOM. The API offers a browser-level way to strengthen protection against cross-site scripting.











