What $sanitize does is that it renders the content as safe html to render with innerHTML, but what it does not do is sanitizing only attributes ...
確定! 回上一頁