Hacker News new | ask | show | jobs
by anykey 4959 days ago
It's really not that difficult if you use a parser + whitelist. You don't have to care about this sort of thing if you limit people to using certain tags/attributes in WYSIWYG editors and other inputs.