Slide 13
Slide 13 text
HTML Templates
Web Components
Working directly with the DOM
no runtime script parsing, smaller XSS attack vector
Hidden from document
cannot traverse into its DOM via JavaScript
Content gets parsed, not rendered
tags aren’t executed, images aren't loaded,
media doesn't play, etc.