JavaScript and client trust
Review browser code as an untrusted-data consumer: preserve origin, context, serialization, and server-authorization boundaries.
This is the complete downloadable file. Open plain text ↗
---
name: javascript
description: "Review browser code as an untrusted-data consumer: preserve origin, context, serialization, and server-authorization boundaries."
---
# JavaScript and client trust
Review browser code as an untrusted-data consumer: preserve origin, context, serialization, and server-authorization boundaries.
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
## Bring to the review
- Owned source or build artifacts
- Browser message contracts
- Content-security and rendering policy
## Review guide
### 1. Map data contexts
Identify where server data, URLs, messages, and generated content enter HTML, script, navigation, or framework rendering contexts.
### 2. Review message authority
Require an explicit sender origin, message shape, and allowed action before a listener changes state or reveals data.
### 3. Check serialization
Ensure data remains data across server rendering, hydration, logs, and client components.
### 4. Keep authorization server-side
Confirm browser controls do not substitute for a server decision about protected resources.
## What to produce
- Source-to-context map
- Message contract review
- Rendering control notes
## Common mistakes
- Treating client checks as access control
- Using generic sanitization without knowing the output context
- Trusting all same-window messages
## Reading and source context
### Resources
- [HTML5 Security Cheat Sheet: Web Messaging](https://vulns.co/research/resources/owasp-browser-message-trust-boundaries/)
- [Next.js data security: server authorization and client-visible data](https://vulns.co/research/resources/nextjs-server-client-data-security/)
- [Trusted Types: typed sinks depend on trustworthy policy creation](https://vulns.co/research/resources/w3c-2026-trusted-types-policy-authority/)
### Diagrams
- [Browser messages need separate trust checks](https://vulns.co/research/diagrams/browser-message-authority-boundaries/)
- [Server disclosure and browser interpretation](https://vulns.co/research/diagrams/server-client-data-consumer-boundaries/)
### Reports
- [Facebook SDK message authentication relied on insecure randomness](https://vulns.co/research/reports/facebook-sdk-message-authentication-randomness-2023/)
- [Meta Pixel cross-window handling lost message and token authority](https://vulns.co/research/reports/meta-pixel-cross-window-authority-binding-2024/)
- [Framework serialization change exposed private HackerOne user attributes](https://vulns.co/research/reports/hackerone-report-json-serialization-data-exposure-2025/)
## Provenance
Editorial guide by vulns.co / GK Data. Updated 2026-10-11.
Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3.
The guide is an editorial synthesis. Linked records preserve their own sources and review dates.
Reader: https://vulns.co/skills/javascript/
The review
What to look for
Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.
Map data contexts
Identify where server data, URLs, messages, and generated content enter HTML, script, navigation, or framework rendering contexts.
Review message authority
Require an explicit sender origin, message shape, and allowed action before a listener changes state or reveals data.
Check serialization
Ensure data remains data across server rendering, hydration, logs, and client components.
Keep authorization server-side
Confirm browser controls do not substitute for a server decision about protected resources.
What to produce
- Source-to-context map
- Message contract review
- Rendering control notes
Common mistakes
- Treating client checks as access control
- Using generic sanitization without knowing the output context
- Trusting all same-window messages
Continue the study
Reading & source context
Editorial notes above connect these references. Open each record for its original source and review date.
Visual models
Connected disclosures
From the field toolkit
Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.