Document: writeln() method

Deprecated: This feature is no longer recommended. Though some browsers might still support it, it may have already been removed from the relevant web standards, may be in the process of being dropped, or may only be kept for compatibility purposes. Avoid using it, and update existing code if possible; see the compatibility table at the bottom of this page to guide your decision. Be aware that this feature may cease to work at any time.

Warning: This method parses its input as HTML, writing the result into the DOM. APIs like this are known as injection sinks, and are potentially a vector for cross-site-scripting (XSS) attacks, if the input originally came from an attacker.

You can mitigate this risk by always passing TrustedHTML objects instead of strings and enforcing trusted types. See Security considerations for more information.

The writeln() method of the Document interface writes text in one or more TrustedHTML or string parameters to a document stream opened by document.open(), followed by a newline character.

Syntax

js
writeln(markup)
writeln(markup, markup2)
writeln(markup, markup2, /* …, */ markupN)

Parameters

markup, …, markupN

TrustedHTML or string objects containing the text to be written to the document.

Return value

None (undefined).

Exceptions

InvalidStateError DOMException

The method was called on an XML document, or called when the parser is currently executing a custom element constructor.

TypeError

A string is passed as one of the parameters when Trusted Types are enforced and no default policy has been defined for creating TrustedHTML objects.

Description

The method is essentially the same as document.write() but adds a newline (information in the linked topic also applies to this method). This newline will only be visible if it is injected inside an element where newlines are displayed. The additional information in document.write() also applies to this method.

Security considerations

The method is a possible vector for Cross-site-scripting (XSS) attacks, where potentially unsafe strings provided by a user are injected into the DOM without first being sanitized. While the method may block <script> elements from executing when they are injected in some browsers (see Intervening against document.write() for Chrome), it is susceptible to many other ways that attackers can craft HTML to run malicious JavaScript.

You can mitigate these issues by always passing TrustedHTML objects instead of strings, and enforcing trusted types using the require-trusted-types-for CSP directive. This ensures that the input is passed through a transformation function, which has the chance to sanitize the input to remove potentially dangerous markup (such as <script> elements and event handler attributes), before it is injected.

Examples

Writing TrustedHTML

This example uses the Trusted Types API to sanitize HTML strings before they are written to a document. You should always use trusted types for passing untrusted strings to unsafe APIs.

The example initially displays some default text and a button. When the button is clicked, the current document is opened, some strings of HTML are converted to TrustedHTML instances and written into the document, and the document is then closed. This replaces the document in the example frame, including the original HTML for the button and the JavaScript that made the update!

HTML

html
<p>Some original document content.</p>
<button id="replace" type="button">Replace document content</button>

JavaScript

First we use the Window.trustedTypes property to access the global TrustedTypePolicyFactory, and use its createPolicy() method to define a policy called "docPolicy".

The new policy defines a transformation function createHTML() for creating the TrustedHTML objects that we will pass to the writeln() method. This method can do anything it likes with the input string: the trusted types API just requires that you pass the input through a policy transformation function, not that the transformation function does anything in particular.

You'd use the method to sanitize the input by removing potentially unsafe features such as <script> tags or event handler attributes. Sanitization is hard to get right, so this process typically uses a reputable third-party library such as DOMPurify.

Here we implement a rudimentary "sanitizer" that replaces < symbols in script opening and closing tags with the &lt; character. The injected strings in this example don't actually contain any harmful elements, so this is purely for demonstration.

js
const policy = trustedTypes.createPolicy("docPolicy", {
  createHTML(string) {
    return string
      .replace("<script", "&lt;script")
      .replace("</script", "&lt;/script");
  },
});

We can then use the TrustedTypePolicy.createHTML() method on the returned policy to create TrustedHTML objects from our original input strings. These are then passed to the writeln() function when the user clicks the button.

js
const replace = document.querySelector("#replace");
const oneInput = "<h1>Out with";
const twoInput = "the old</h1>";
const threeInput = "<pre>in with";
const fourInput = "the new!</pre>";

replace.addEventListener("click", () => {
  document.open();
  document.writeln(policy.createHTML(oneInput));
  document.writeln(policy.createHTML(twoInput), policy.createHTML(threeInput));
  document.writeln(policy.createHTML(fourInput));
  document.close();
});

Results

Click the button. Note that a newline is added after each call to writeln(), but this will only be visible inside the <pre> element because its layout preserves whitespace by default.

Specifications

Specification
HTML
# dom-document-writeln-dev

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
writeln
Deprecated
Chrome – Partial support
Chrome 1 – 44 (Release date: 2008-12-11)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Chrome – Full support
Chrome 45 (Release date: 2015-09-01)
footnote Full support
Edge – Full support
Edge 12 (Release date: 2015-07-29)
footnote Full support
Firefox – Partial support
Firefox 1 – 68 (Release date: 2004-11-09)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Firefox – Full support
Firefox 69 (Release date: 2019-09-03)
footnote Full support
Opera – Partial support
Opera 12.1 – 50 (Release date: 2012-11-20)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Opera – Full support
Opera 51 (Release date: 2018-02-07)
footnote Full support
Safari – Partial support
Safari 1 – 10.1 (Release date: 2003-06-23)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Safari – Full support
Safari 11 (Release date: 2017-09-19)
footnote Full support
Chrome Android – Partial support
Chrome Android 18 – 44 (Release date: 2012-06-27)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Chrome Android – Full support
Chrome Android 45 (Release date: 2015-09-01)
footnote Full support
Firefox for Android – Partial support
Firefox for Android 4 – 68 (Release date: 2011-03-29)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Opera Android – Partial support
Opera Android 12.1 – 46 (Release date: 2012-10-09)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Opera Android – Full support
Opera Android 47 (Release date: 2018-07-23)
footnote Full support
Safari on iOS – Partial support
Safari on iOS 1 – 10.3 (Release date: 2007-06-29)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Safari on iOS – Full support
Safari on iOS 11 (Release date: 2017-09-19)
footnote Full support
Samsung Internet – Partial support
Samsung Internet 1 – 4.2 (Release date: 2013-04-27)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
Samsung Internet – Full support
Samsung Internet 5 (Release date: 2016-12-15)
footnote Full support
WebView Android – Partial support
WebView Android 4.4 – 44 (Release date: 2013-12-09)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
WebView Android – Full support
WebView Android 45 (Release date: 2015-09-01)
footnote Full support
WebView on iOS – Partial support
WebView on iOS 1 – 10.3 (Release date: 2007-06-29)
footnote Partial support
footnote Only supported for HTMLDocument, not all Document objects.
WebView on iOS – Full support
WebView on iOS 11 (Release date: 2017-09-19)
footnote Full support
Requires TrustedHTML instance when trusted types are enforced
Deprecated
Chrome – Full support
Chrome 86 (Release date: 2020-10-20)
footnote Full support
Edge – Full support
Edge 86 (Release date: 2020-10-09)
footnote Full support
Firefox – Full support
Firefox 148 (Release date: 2026-02-24)
footnote Full support
Opera – Full support
Opera 72 (Release date: 2020-10-21)
footnote Full support
Safari – Full support
Safari 26 (Release date: 2025-09-15)
footnote Full support
Chrome Android – Full support
Chrome Android 86 (Release date: 2020-10-20)
footnote Full support
Firefox for Android – Full support
Firefox for Android 148 (Release date: 2026-02-24)
footnote Full support
Opera Android – Full support
Opera Android 61 (Release date: 2020-12-07)
footnote Full support
Safari on iOS – Full support
Safari on iOS 26 (Release date: 2025-09-15)
footnote Full support
Samsung Internet – Full support
Samsung Internet 14 (Release date: 2021-04-17)
footnote Full support
WebView Android – Full support
WebView Android 86 (Release date: 2020-10-20)
footnote Full support
WebView on iOS – Full support
WebView on iOS 26 (Release date: 2025-09-15)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
Partial support
Partial support
Deprecated. Not for use in new websites.
Has more compatibility info.