XSS
<script src="https://cdn.bootcdn.net/ajax/libs/dompurify/2.3.0/purify.js"></script>
<strong>${DOMPurify.sanitize(data.content[i].mbName)}</strong>
//昵称输入框的监听document.querySelector("#name").addEventListener("keydown", debounce(function () {const content = DOMPurify.sanitize(this.value.trim());if (content.length <= 0) {$("#name").popover("show");} else if (testEmail($("#emali").val())) {$("#name").popover("hide");document.querySelector("#submit").className = "btn btn_submit_scuess";} else {$("#name").popover("hide");}}, 100));
转义html
function mdToHtml(markdownText) {return DOMPurify.sanitize(marked(markdownText, {gfm: true}));}
${mdToHtml(data.content[i].mbContent)}
