Strip HTML tags from a user-supplied string to prevent XSS. Uses a multi-pass loop to handle nested tag reconstruction attempts (e.g. <scr<script>ipt>). Returns plain text โ callers must apply escapeHtml() at their render sites so escaping happens exactly once.
Strip HTML tags from a user-supplied string to prevent XSS. Uses a multi-pass loop to handle nested tag reconstruction attempts (e.g.
<scr<script>ipt>). Returns plain text โ callers must applyescapeHtml()at their render sites so escaping happens exactly once.