Chapter 19. Frontend Security Considerations
Security is another area of the frontend that should be top of mind as you implement new features. Security is extremely important and encompasses such detail as to warrant its own book, but this chapter will cover enough for you to know what to be aware of.
You’ve already learned about some of the vulnerabilities and remedies for security on the backend in Chapter 8. The frontend is usually the most accessible part of a product and can act as a gateway for server attacks. Now you have to consider things like browser vulnerabilities and ways malicious users can manipulate the flow of how the app should work to gain more access than they should have. Think about how you store and transmit data on the frontend because everything that loads in the browser is accessible by users if they just open the developer tools. You and the team need to find a balance between user convenience and security.
In this chapter, I’ll cover:
-
More of the OWASP Top 10
-
Common vulnerability vectors
-
How to attack an app
-
Ways attackers can get information directly from the browser
-
Strategies to reduce the number of attack possibilities
You’ll need to check with any local or regional data-privacy and compliance laws and rules that your product is governed by as well, such as PCI DSS, HIPAA, and GDPR (all mentioned previously in Chapter 8). These regulations can be more strict than regular best practices, so keep that in mind.
An overlooked skill is knowing ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access