tomayac’s avatartomayac’s Twitter Archive—№ 4,122

  1. Don't use el.textContent to strip HTML tags, or you're pwnd by an #XSS: bit.ly/PD2exF (via @ebidel on G+) #JavaScript