# Rendering HTML similar to Markdown

**URL:** <https://community.plotly.com/t/rendering-html-similar-to-markdown/6232>\
**Category:** Dash Python\
**Created:** [October 11, 2017, 6:50pm UTC](https://community.plotly.com/t/rendering-html-similar-to-markdown/6232 "2017-10-11T18:50:38Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![chriddyp](https://sea2.discourse-cdn.com/flex024/user_avatar/community.plotly.com/chriddyp/32/16855_2.png) [@chriddyp](https://community.plotly.com/u/chriddyp)\
**Post date:** [October 11, 2017, 7:05pm UTC](https://community.plotly.com/t/rendering-html-similar-to-markdown/6232/2 "2017-10-11T19:05:42Z")

</div>

For security reasons (XSS), it is not possible to render raw HTML. However, a current workaround is to display the HTML string inside the `srcDoc` attribute of an IFrame. Here’s an example:

 ![image](https://us1.discourse-cdn.com/flex024/uploads/plot/original/2X/0/0ea1ceecd64a564ec5427c576b7dc09a0c052146.png)

```auto
import dash
import dash_html_components as html

app = dash.Dash()

app.layout = html.Div([
    html.Iframe(
        # enable all sandbox features
        # see https://developer.mozilla.org/en-US/docs/Web/HTML/Element/iframe
        # this prevents javascript from running inside the iframe
        # and other things security reasons
        sandbox='',
        srcDoc='''
            <h3>IFrame</h3>
            <script type="text/javascript">
                alert("This javascript will not be executed")
            </script>
        '''
    )
])

if __name__ == ' __main__':
    app.run_server(debug=True)

```

---

_[View the full topic](https://community.plotly.com/t/rendering-html-similar-to-markdown/6232)._
