Security Risk: Single-Page Applications | Andreas Falk (EN)

Опубликовано: 30 Сентябрь 2024
на канале: JAVAPRO
260
5

Single-page applications are very popular nowadays, and for this reason, current frontends are predominantly executed as Javascript applications entirely in the user's web browser. However, from a security perspective, SPAs bring a much higher risk compared to server-side web applications such as Spring MVC. In this talk, we will look at the popular SPA libraries Angular, React and Vue and take a closer look at their security aspects. In particular, we will look at security risks such as cross-site scripting (XSS), cross-site request forgery (CSRF), token-based authentication risks, and CORS misconfigurations. In order not to leave developers unprotected in the rain, we will analyze the built-in defenses of the various SPA libraries or frameworks and show what steps are required beyond that for developers. So be prepared for some XSS popups to appear in your favorite SPAs. The talk is aimed at software developers, architects, and anyone interested in security alike. Basic prior knowledge of how web applications work is necessary to understand the talk. Knowledge of a programming language such as Java or Javascript is helpful, but not mandatory.

➜ Abonniere JAVAPRO und verpasse keine News:
https://bit.ly/YouTube-JAVAPRO-abonni...


▬ Über uns: ▬

JAVAPRO ist das Magazin für professionelle Java-Entwicklung in der Praxis.
Über das Magazin hinaus ist JAVAPRO Veranstalter der jährlich stattfindenden Entwickler-Konferenz JCON. Auf der JCON stehen Core Java, Enterprise Java, Microservices, APIs und Frameworks im Fokus.
Auf diesem Kanal finden sich Interviews, Sessions, Tipps & Tricks und alles, was das (Java)-Entwickler-Herz begehrt.

➜ Jetzt kostenlos Magazin anfordern:
https://javapro.io


▬ Folge uns auf Social Media: ▬

Twitter:   / javapromagazin  
Facebook:   / javapromag  


➜ Danke fürs Abo & fürs Zusehen!