/** * Escape HTML special characters for safe insertion into the DOM. * * Accepts any value — null, undefined, and non-strings are coerced * to a string first (null/undefined become ''). */ export function escapeHtml(value: unknown): string { if (value === null || value === undefined) return ''; const str = typeof value === 'string' ? value : String(value); return str .replace(/&/g, '&') .replace(//g, '>') .replace(/"/g, '"'); }