Sanitizing
HTML is sanitized before it is inserted. That is the safe default and it is the one to keep for anything that
originated with a user, whether it arrived from a form, a database or an API.
For markup you author yourself, prefix the data-key with trust: to skip sanitizing for that one
binding. Setting $bindary.trustHTML disables sanitizing for every b-html on the
page, which is a decision worth making deliberately rather than reaching for when a tag gets stripped.
<!-- sanitized -->
<p b-html="content"></p>
<!-- rendered as-is -->
<p b-html="trust:content"></p>
Trusting a data-source means any script or event handler in that data will run. Only trust markup you
control end to end.
The built-in sanitizer can be replaced outright by assigning your own function to
$bindary.sanitizer, if you already have a policy you would rather apply.