Hacker News new | ask | show | jobs
by ashishsingal 1180 days ago
there's "HTML (.add_html)" in the docs - "Renders raw HTML. This is meant to be an escape hatch for when you need to render something that isn't supported by PyVibe." I'm guessing this isn't sanitized and we trust the dev. After all, they can do "eval" in Python which is much riskier than raw HTML :)
1 comments

All of the components support rendering arbitrary HTML, which is exactly the problem.