In memory of Saber Rastikerdar — creator of · Vazirmatn, the open typeface he gave the Persian web and asked nothing for.
Skip to content

Security

Client-side threats, mitigations, and safe defaults — including auth.

Part: 05 · Reliability & Quality · Priority: Critical

Taxonomy

Second-level groups and their articles. Each article is a standalone entry following the template; its filename is the kebab-case form of the title.

The Security Model

  • Same-Origin Policy
  • CORS
  • Isolation (COOP/COEP)

Injection Attacks

  • Cross-Site Scripting (XSS)
  • DOM-Based XSS
  • HTML/Template Injection
  • Sanitization & Encoding

Request Attacks

  • Cross-Site Request Forgery
  • Clickjacking
  • Client-Edge SSRF

Content Security

  • Content Security Policy
  • Trusted Types
  • Subresource Integrity

Authentication & Sessions

  • Session Management
  • Token Types (JWT, opaque)
  • Token Storage Trade-offs
  • OAuth & OIDC Flows
  • Client Auth (guards, refresh)

Supply Chain

  • Dependency Vulnerabilities
  • Lockfiles & Provenance
  • Third-Party Script Risk

Privacy

  • Data Handling & PII
  • Consent & Tracking
  • Regulatory Compliance

Index only. One canonical home per concept — overlapping ideas are owned here and cross-linked from other domains, never duplicated.

Peer-reviewed engineering decisions · MIT licensed