8
I have been reading that you HTML encode on the way back from the server to the client (I think?) and this will prevent many types of XSS attacks. However, I don't understand at all. The HTML is still going to be consumed and rendered by the browser right?
How is this stopping anything?
I've read about this in multiple locations, websites and books, and nowhere does it actually explain why this works.