#

frontend

2 posts

Moving JWTs out of localStorage: the surprises waiting in ActionController::API

A JS-readable token in localStorage is one XSS away from account takeover. Moving it into an HttpOnly cookie is the well-known fix but ActionController::API has no cookies, no CSRF, and a few other surprises waiting on the first commit.

Jul 30, 202613 min readsecurity
An old key being lifted off a hook on the wall and locked into a wall safe.

CSP nonces vs. 'unsafe-inline': the silent override that broke our admin UI

A nonce and 'unsafe-inline' in the same CSP directive: the browser silently drops 'unsafe-inline' by spec. Debugging a policy that quietly broke production.

Jul 30, 202610 min readsecurity
Two locks side by side on a door, only one is actually engaged. The other is decorative.