Hacker News new | ask | show | jobs
by wewtyflakes 241 days ago
Wouldn't that open the floodgates by allowing code that could itself call `setHTML` again but then further revise the args to escalate its privileges?