- Escape sender name via escapeHtml in innerHTML template - Set message content via textContent instead of innerHTML injection - Prevents HTML/script injection from user input or LLM responses
- Escape sender name via escapeHtml in innerHTML template - Set message content via textContent instead of innerHTML injection - Prevents HTML/script injection from user input or LLM responses