You can throw away innerHTML and replace it with the new setHTML(), which has a built-in sanitizer. Here's how it works:
@firefoxwebdevs Fantastic! Can’t wait for this to be in baseline!