google / tour-of-wgsl

https://google.github.io/tour-of-wgsl/
BSD 3-Clause "New" or "Revised" License
107 stars 19 forks source link

Update check_wgsl_feature.html DOM text reinterpreted as HTML #92

Closed Shivam7-1 closed 6 months ago

Shivam7-1 commented 6 months ago

By using innerText, it will avoid the risk of HTML injection, as these properties automatically escape any HTML special characters in the provided text. This helps prevent cross-site scripting (XSS) vulnerabilities by treating the input as plain text rather than interpreted HTML. Always be cautious when dealing with user input or dynamic content to prevent security risks.