You can throw away innerHTML and replace it with the new setHTML(), which has a built-in sanitizer. Here's how it works:
@firefoxwebdevs It's back! 🎉