Intent to prototype: Sanitizer API

164 views
Skip to first unread message

Tom Schuster

unread,
Oct 17, 2025, 10:34:36 AMOct 17
to dev-pl...@mozilla.org

Summary: The Sanitizer API provides new methods for HTML manipulation. As an example, element.setHTML() allows developers to insert HTML like element.innerHTML but without the security risks (like XSS). We have a pretty much finished implementation that we want to enable in Nightly soon.
Bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1650370
Specification: https://github.com/WICG/sanitizer-api
Standards Body: WhatWG/HTML stage 2 (https://github.com/whatwg/html/issues/7197)
Platform coverage: all
Preference: dom.security.sanitizer.enabled
DevTools bug: n/a
Link to standards-positions discussion: https://github.com/mozilla/standards-positions/issues/106
Other browsers:

web-platform-tests: https://wpt.fyi/results/sanitizer-api


Reply all
Reply to author
Forward
0 new messages