Web Foundations

Browser security model

Browsers enforce multiple security boundaries. CORS controls whether browser JavaScript can read cross-origin responses; it does not replace server authorization.

  • Understand same-origin policy.
  • Treat CORS as a browser read-access policy.
  • Use CSRF defenses for cookie-authenticated state-changing actions.
  • Use appropriate security headers for the application.
Lesson complete?Use the next lesson to continue the learning path.