Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion index.bs
Original file line number Diff line number Diff line change
Expand Up @@ -814,4 +814,4 @@ Please see [[WRITING-ASSISTANCE-APIS#security]] for a discussion of security con
The text returned by these APIs is generated by a model and must be treated as untrusted, whether the model runs locally or in the cloud. Because these models emit text, and text can contain HTML-significant characters or well-formed markup, the output can include markup <em>even when the input was plain text</em>; the model does not sanitize its output and is not a security boundary. An attacker who can influence the input (e.g., user-generated content that is being translated) can craft input that induces markup in the output.

Web developers should therefore not insert this output into a document as HTML (for example via {{Element/innerHTML}}, {{Element/insertAdjacentHTML()}}, or `document.write()`), nor otherwise interpret it as code, without first sanitizing it, e.g. using {{Element/setHTML()}} or by assigning it to {{Node/textContent}} where structure is not required. This complements the
input-side guidance against treating web-developer-provided context as instructions in each "the algorithm" section (for example, [[#summarizer-algorithm]]).
input-side guidance against treating web-developer-provided context as instructions in each "the algorithm" section (for example, [[#translator-algorithm]]).
Loading