Security
Client-side threats, mitigations, and safe defaults — including auth.
Part: 05 · Reliability & Quality · Priority: Critical
Taxonomy
Second-level groups and their articles. Each article is a standalone entry following the template; its filename is the kebab-case form of the title.
The Security Model
- Same-Origin Policy
- CORS
- Isolation (COOP/COEP)
Injection Attacks
- Cross-Site Scripting (XSS)
- DOM-Based XSS
- HTML/Template Injection
- Sanitization & Encoding
Request Attacks
- Cross-Site Request Forgery
- Clickjacking
- Client-Edge SSRF
Content Security
- Content Security Policy
- Trusted Types
- Subresource Integrity
Authentication & Sessions
- Session Management
- Token Types (JWT, opaque)
- Token Storage Trade-offs
- OAuth & OIDC Flows
- Client Auth (guards, refresh)
Supply Chain
- Dependency Vulnerabilities
- Lockfiles & Provenance
- Third-Party Script Risk
Privacy
- Data Handling & PII
- Consent & Tracking
- Regulatory Compliance
Index only. One canonical home per concept — overlapping ideas are owned here and cross-linked from other domains, never duplicated.