Sessions, local storage, and cache validation boundaries. The three lessons in this section follow a single inspection workflow, so the request, browser behavior, server decision, and visible result can be checked together.
Lessons
- Sessions and CSRF: keep identity on the server — Model a session cookie and a separate write token without trusting browser storage.
- Browser storage: save convenience data without storing credentials — Treat local storage as untrusted, optional, and visible to page scripts.
- HTTP caching: validate a changed representation with an ETag — Return 304 only when the client's validator matches the current representation.
- Untrusted output: escape by context and constrain scripts — Keep user text as text, then add a script policy as another boundary.
- Authorization: check permission for this record on every request — Distinguish a signed-in identity from authority over case 47.
Continue across the track
Requests and Browser Foundations; Browser Interactions; Quality and Release; Web Technology: Projects; Web Development: Quizzes.
Broader connections
Data Persistence; Backend and API Systems; Offline and Device Capabilities.
Advanced connections
Identity and Application Security.
