Several development teams of
flagship Google applications have
adopted these design patterns and
coding guidelines. They have established
static enforcement that all
HTML markup is produced by strictly
contextually auto-escaped templates,
and they have disallowed direct use of
certain injection-prone Web-platform
APIs such as innerHTML.