Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
jraph
10 days ago
|
parent
|
context
|
favorite
| on:
Goodbye InnerHTML, Hello SetHTML: Stronger XSS Pro...
Indeed, as any browser API, it might be for in a few years (months if happy with the most recent versions), and we may have polyfills in the meantime.
help
tuyiown
10 days ago
|
next
[–]
I wouldn't advise polyfills on this one, it entirely depends on the browser ability to evaluate cross scripting and cross origin rule on a arbitrary snippet. This is not a convenience API.
reply
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: