You can throw away innerHTML and replace it with the new setHTML(), which has a built-in sanitizer. Here's how it works:
@firefoxwebdevs this is fantastic! This has bitten me in the past, and I'm excited to be able to use this soon!