I obviously know nothing about this, but I still find it fascinating. Or am I off my block.
https://developer.mozilla.org/en-US/docs/Web/Security/Attack...
Hmmm...
for example, a search query, or a redirect url, or a million other things
Whether I generate a whole page or generate a partial page and then add HTML to it is equivalent from a safety perspective.
Markdown implementations can do any of that, only allowing a whitelist of HTML elements (GFM), or not allowing HTML at all.
If you include user-provided data, then you should sanitize it for HTML.
Solutions in the form of pre-existing HTML sanitisation libraries have existed for years but countless websites still manage to get XSS'd every year because not everyone capable of writing code is capable of writing secure code.
2. Because it’s really easy to fuck up and leak attacker controlled content in markup, especially when the environment provides tons of tools to do things wrong and none to do things right. IME even when the environment provides tons of tools to do things right it’s an uphill battle (universe, idiots, yadda yadda).