ShopTalk Show · ShopTalk

March 2, 2026·1 hr 2 min·5 clips
The Sanitizer API's setHTML method ensures security by default, preventing cross-site scripting even with custom configurations.
The cold open starts with XSS jokes, which tells you pretty much where this episode lives. Then Frederick Braun joins from Mozilla, says he manages the Firefox application security team, and admits he still likes building web security APIs when he can. The focus is the sanitizer API, fresh in Firefox a couple of days before they recorded. Chris wants it in code, not hand waving, so he reads examples out loud with paragraphs, anchors, and Dave-flavored custom elements. The whitelist bit gets awkward quickly. If you list allowed elements, did you just throw away the browser's default set? Attributes are their own little tangle. Frederick explains that they can be allowed globally or scoped so different elements get different sets. Useful, yes. Also the kind of config dictionary that better have comments, because somebody will have to touch it later. Data attributes sound harmless until they aren't. The API can allow them with a Boolean switch, and Frederick thinks they are off by default because apps can attach meaning to them. The attribute itself is not the XSS bug. The problem starts when another script on the page trusts it and does something unsafe. The whole conversation stays nicely grounded: what does a front-end developer actually allow, and what are they taking on when they do? Near the end, Frederick points people to frederickbraun.de and his Mastodon handle at security.plumbing. Chris catches the URL, and they roll out through setHTML jokes and the usual ShopTalk paths.

As heard by us

A loose, practical ShopTalk conversation about the Sanitizer API and the tradeoffs behind safer HTML handling.

ShopTalk Show turns a new web security API into the kind of practical craft conversation it does best. Dave Rupert and Chris Coyier keep the mood loose, with just enough bad security jokes, while Frederick Braun from Mozilla's Firefox application security team explains what the…

Read the full review in PlayNext →

Why you'd press play

You want the Sanitizer API explained without the security-jargon fog.

Read the full recommendation in PlayNext →
Listen to the show on