• do
InterCourses
CoursesBlogs
0
← DOM Manipulation with JavaScript
○The page is a tree○Exercise: follow the document reference○Load a script when the page is ready○Exercise: initialize a deferred script○Find one element by id or CSS selector○Exercise: select a notice and label○Compare DOM properties, HTML attributes, and node types○Exercise: inspect a room input and its nodes✦Module Quiz
○Find every match with querySelectorAll○Exercise: label every trail stop○Move from a child to its relatives○Exercise: trace a nested card○Check for missing elements and search within a card○Exercise: update only the chosen card○Compare a live HTMLCollection with a static NodeList○Exercise: safely expand a live collection✦Module Quiz
●Safe text and HTML○Exercise: render a safe notice○Read and change link attributes○Exercise: update an accessible link○Data attributes and conditional text○Exercise: announce session availability○Boolean attributes and DOM properties○Exercise: unlock a volunteer sign-up✦Module Quiz
○Add, remove, and check classes○Exercise: mark a favourite card○Toggle a panel accessibly○Exercise: toggle the help panel○Inline styles, classes, and hidden○Exercise: style and hide a notice○Change a CSS custom property from JavaScript○Exercise: change a workshop card accent✦Module Quiz
○Create and Append a Text Node○Exercise: Add a Reading List Item○Place Nodes Before and Between○Exercise: Order the Workshop Agenda○Remove, Replace, and Clear Safely○Exercise: Refresh a Museum Display○Clone a Card and Insert a Batch○Exercise: Clone Two Exhibit Cards✦Module Quiz
○Listen for Clicks with a Named Handler○Exercise: Check Library Hours○Event Target, Current Target, and Delegation○Exercise: Delegate Pantry Actions○Keyboard Events Without Trapping Keys○Exercise: Search the Recipe Box○Once, Remove, and Bubble○Exercise: Control Workshop Notifications✦Module Quiz
○Read a field while someone types○Build a live name preview○Handle submit without leaving the page○Validate a library request○Keep a selection in sync on change and reset○Sync a preference and its reset state○Read multiple checked values with FormData○Build a checkbox-based garden request✦Module Quiz
○Filter a list as someone types○Build a live trail finder○Toggle an accessible disclosure○Build a guide menu disclosure○Create and remove items with one delegated listener○Build a neighborhood task board○Sort a workshop table with accessible buttons○Build an accessible sortable resource table✦Module Quiz
○Read selectable cards and detail updates○Build directory cards and a selected profile○Trace live search and an empty state○Add live search to the community directory○Trace safe additions and delegated removal○Add and remove community directory cards✦Module Quiz
○Read and update a live itinerary○Build the workshop itinerary○Add a validated item through a form○Add a workshop session○Filter and remove live entries○Finish the workshop planner✦Module Quiz
○Fetch JSON and render safe text○Exercise: load recipe cards○Handle loading, empty, and failed responses○Exercise: handle alert states○Build a query with URLSearchParams○Exercise: search the catalog○Abort outdated requests○Exercise: keep the latest result✦Module Quiz
○Load a dashboard from an offline API fixture○Build an events dashboard○Query a dashboard with URLSearchParams○Add event search to the dashboard○Retry requests without stale results○Finish a resilient event dashboard✦Module Quiz

Safe text and HTML

A community board prints a submitted note. The note is data, not markup: the browser must show its angle brackets literally.

What the code does

textContent replaces a node’s children with plain text; angle brackets in the assigned string are displayed literally rather than parsed as tags. innerHTML parses the assigned string as HTML and can create elements, including unsafe markup when the string comes from a user. Reserve innerHTML for carefully controlled, trusted markup; do not use it for visitor input. Reading .textContent returns descendant text, including text in hidden descendants, rather than an HTML source string.

In script.js, this is the important part of the already-working preview:

javascript
const boardNote = document.querySelector("#board-note");
const visitorNote = "I brought <seedlings> today"; // Pretend this came from a form.
boardNote.textContent = visitorNote;

Try it in the preview

The preview shows the literal <seedlings> characters; there is no new seedlings element. Change the string to "<strong>hello</strong>" and Run again: you should see the tags printed, not bold text. Restore the original string afterward.

When a string comes from a person or remote data, which property keeps it as text? textContent. Why not innerHTML here? It would parse the string as markup.

The next lesson gives you a different page to build from a starter.

Loading editor…
READY
intercourses
javascript