With `const clean = DOMPurify.sanitize(input); context.innerHTML = clean;` your linter suddenly needs to do complex code analysis and keep track if each variable passed to `context.innerHTML` is clean or tainted.
https://developer.mozilla.org/en-US/docs/Web/API/Trusted_Typ...
1. <https://pchiusano.github.io/2014-10-11/defensive-writing.htm...>
Doesn't seem obvious unless your dutch.
Especially as the first things I would think obvious is: if breaking the behaviour of innerHTML is not a concern for your software why keep it at all? Delete the property or make it readonly.
I don't know what that means.
> if breaking the behaviour of innerHTML is not a concern for your software why keep it at all?
For the reason that they said.
I believe this is a reference to the old "Zen of Python," which one gets by running `import this` in the Python REPL.
"""
There should be one-- and preferably only one --obvious way to do it.
Although that way may not be obvious at first unless you're Dutch.
"""