Avoid XSS with the help of Joi validator
const xss = require('@ncardez/joi-xss');
const Joi = require('joi').extend(xss('object'), xss('array'), xss('string'));
const input = { name: "<p>hola</p>" };
// Return result.
const { value } = Joi.object().unknown(true).xss().validate(input);
// value.name === '<p>hola</p>'
// You can also pass options.
const { value } = Joi.object().unknown(true).xss({ stripIgnoreTag: true }).validate(input);
// value.name === 'hola'