Markdown sanitizer allows onclick
Review this React TypeScript markdown renderer.
What a strong answer looks like
Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.
0:00 of about 22 min
Mark a line and say what kind of problem it is.0 findings
1import DOMPurify from 'dompurify';
2
3function Note({ markdown }: { markdown: string }) {
4 const html = mdToHtml(markdown);
5 const clean = DOMPurify.sanitize(html, { ADD_ATTR: ['onclick'] });
6 return <div dangerouslySetInnerHTML={{ __html: clean }} />;
7}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.