--- name: javascript description: "Review browser code as an untrusted-data consumer: preserve origin, context, serialization, and server-authorization boundaries." --- # JavaScript and client trust Review browser code as an untrusted-data consumer: preserve origin, context, serialization, and server-authorization boundaries. Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question. ## Bring to the review - Owned source or build artifacts - Browser message contracts - Content-security and rendering policy ## Review guide ### 1. Map data contexts Identify where server data, URLs, messages, and generated content enter HTML, script, navigation, or framework rendering contexts. ### 2. Review message authority Require an explicit sender origin, message shape, and allowed action before a listener changes state or reveals data. ### 3. Check serialization Ensure data remains data across server rendering, hydration, logs, and client components. ### 4. Keep authorization server-side Confirm browser controls do not substitute for a server decision about protected resources. ## What to produce - Source-to-context map - Message contract review - Rendering control notes ## Common mistakes - Treating client checks as access control - Using generic sanitization without knowing the output context - Trusting all same-window messages ## Reading and source context ### Resources - [HTML5 Security Cheat Sheet: Web Messaging](https://vulns.co/research/resources/owasp-browser-message-trust-boundaries/) - [Next.js data security: server authorization and client-visible data](https://vulns.co/research/resources/nextjs-server-client-data-security/) - [Trusted Types: typed sinks depend on trustworthy policy creation](https://vulns.co/research/resources/w3c-2026-trusted-types-policy-authority/) ### Diagrams - [Browser messages need separate trust checks](https://vulns.co/research/diagrams/browser-message-authority-boundaries/) - [Server disclosure and browser interpretation](https://vulns.co/research/diagrams/server-client-data-consumer-boundaries/) ### Reports - [Facebook SDK message authentication relied on insecure randomness](https://vulns.co/research/reports/facebook-sdk-message-authentication-randomness-2023/) - [Meta Pixel cross-window handling lost message and token authority](https://vulns.co/research/reports/meta-pixel-cross-window-authority-binding-2024/) - [Framework serialization change exposed private HackerOne user attributes](https://vulns.co/research/reports/hackerone-report-json-serialization-data-exposure-2025/) ## Provenance Editorial guide by vulns.co / GK Data. Updated 2026-10-11. Library snapshot: 2026-10-04; commit d5550c7891119cf1379e235721541c947850a3b3. The guide is an editorial synthesis. Linked records preserve their own sources and review dates. Reader: https://vulns.co/skills/javascript/