Firefox Tomorrow

web api instance method

TrustedTypePolicy: createHTML() method

View on MDN ↗

Available in workers

The createHTML() method of the TrustedTypePolicy interface creates a TrustedHTML object using a policy created by createPolicy().

Syntax

createHTML(input)
createHTML(input, args)

Parameters

  • input
    • : A string containing the string to be sanitized by the policy.
  • args Optional
    • : Additional arguments to be passed to the function represented by TrustedTypePolicy.

Return value

A TrustedHTML object.

Exceptions

Examples

In the below example a string containing a potentially dangerous script is used as the input for createHTML(). Dangerous code inserted by a user could then be sanitized before insertion into any injection sink.

const escaped = escapeHTMLPolicy.createHTML("<img src=x onerror=alert(1)>");

Specifications

SpecificationsStandards references are available on the canonical MDN page.

Browser compatibility

Browser compatibilityCompatibility data is available on the canonical MDN page.