CORS, CSRF, and XSS: different threat models

Coming soon
IntermediateDifficulty: Intermediate
DeveloperAudience: Developer
Security practitionerAudience: Security practitioner
Secure accessPurpose: Secure access

Wave 3 · Mechanisms · T02.09

Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

The question

How can you separate CORS, CSRF, and XSS threat models?

What we will work through

Separate CORS, CSRF, and XSS threat models.

Before you begin

Previously covered: How automatically sent credentials enable CSRF.

Articles

Color theme

Language

Home