This question evaluates knowledge of security best practices in React applications.
01
01
Understand the problem
securityxssjsxbest practices
02
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Stuck? AI Nudge Available
Get a conceptual hint to guide your logic without spoiling the final implementation.
03
03
Study the solution
The solution is waiting
Give it an honest attempt first — then compare your thinking with the full walkthrough.
04
04
Read the code
Escaped by default; sanitize raw HTML
export default function App() {
const userInput = '<img src=x onerror="alert(1)">';
// ✅ SAFE: rendered as literal text, the tag does not execute
const safe = <p>{userInput}</p>;
// ⚠️ ONLY with sanitized HTML (e.g. DOMPurify.sanitize(html)):
// <div dangerouslySetInnerHTML={{ __html: clean }} />
return (
<div style={{ padding: 24, fontFamily: "system-ui" }}>
{safe}
<small>The markup above is shown as text, not executed.</small>
</div>
);
}05
05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.