자바스크립트 개발자, 웹 애플리케이션 침투 테스터, 보안 엔지니어 중 어떤 일을 맡든 브라우
저
DOM
과 웹 애플리케이션에서 그 역할을 깊이 이해하는 것은 애플리케이션의 표현 계층에
서 나타나는 취약점을 발견하는 데 중요하다.
DOM
이 최종 사용자에게 배포되는 자바스크립
트 기반 애플리케이션 프레임워크임을 고려하고 모든 스크립트 관련 보안 허점이 부적절한 자
바스크립트 때문에 발생하는 것이 아니며 때로는 브라우저
DOM
이 부적절하게 구현된 결과임
을 명심하자.
3.5
SPA
프레임워크
오래된 웹사이트에는
DOM
을 다루는 애드혹
ad
hoc
스크립트와 재사용한
HTML
템플릿 코드가
혼재되어 있는 경우가 많다. 이것은 확장성 있는 모델이 아니며 최종 사용자에게 정적 컨텐츠
를 제공할 때는 가능한 방식이었지만 복잡하고 로직이 많이 구현된 애플리케이션을 제공하는
데에는 부적합하다.
그 당시 데스크톱 애플리케이션 소프트웨어들은 기능성이 견고하고 사용자가 애플리케이션 상
태를 저장하고 유지할 수 있었다. 많은 회사에서 사용 편의성과 해적판 ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month, and much more.
O’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
I wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
I’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
I'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.