Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One big difference and why I've been experimenting with JSX[1] is that in that example, if the `text` comes from an untrusted source it can lead to XSS, which TinyJS prevents (I checked)!

[1] https://x.com/FPresencia/status/1838176000267452704



Even if it comes from a trusted source, you usually want a good distinction between html interpolation and just-text chunks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: