const sanitized = DOMPurify.sanitize(input.value);
const html = `
<meta http-equiv=Content-Security-Policy content="script-src 'nonce-xyz'">
<p>Welcome to my homepage! Here are some info about me:</p>
<script nonce=xyz src="./main.js"><\/script>
len.textContent = location.href.length;
