Today I learned about Trusted Types: specification.website/spec/securit... Which looks like a great way to prevent XSS in many cases. There are so many specifications like this I didn't know about before building this site...
Trusted Types · Website Spec
Trusted Types make the browser reject plain strings at DOM injection sinks like innerHTML, demanding a vetted typed value instead. Switched on with two CSP directives, it neutralises a whole class of ...
specification.website