Web Security for Frontend Devs · Part 27 — Trusted Types: Killing DOM-XSS by Construction
Bonus track: instead of remembering to sanitize at every sink, Trusted Types makes the browser reject raw strings at innerHTML, eval, and script.src — values must come from a registered policy. Enforce vs report-only, with a live simulator.