Skip to content

Instantly share code, notes, and snippets.

@kzgolden-pba
kzgolden-pba / controllers.application.js
Last active March 1, 2018 17:55
htmlSafe Not Safe
import Ember from 'ember';
export default Ember.Controller.extend({
appName: 'Ember Twiddle',
htmlToRender: '',
actions: {
loadArbitraryScriptTag() {
alert('action fired');
this.set('htmlToRender', Ember.String.htmlSafe('<svg witdth="300" height="300" onclick="alert(\'XSS\');">'));
}