This is apparently not done browser side but server side.
As in, user can upload whatever they wish and it will be shown to them and ran, as JS, fully privileged and all.