{
  "slug": "javascript",
  "name": "JavaScript and client trust",
  "category": "Application",
  "summary": "Review browser code as an untrusted-data consumer: preserve origin, context, serialization, and server-authorization boundaries.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Owned source or build artifacts",
    "Browser message contracts",
    "Content-security and rendering policy"
  ],
  "review": [
    {
      "title": "Map data contexts",
      "body": "Identify where server data, URLs, messages, and generated content enter HTML, script, navigation, or framework rendering contexts."
    },
    {
      "title": "Review message authority",
      "body": "Require an explicit sender origin, message shape, and allowed action before a listener changes state or reveals data."
    },
    {
      "title": "Check serialization",
      "body": "Ensure data remains data across server rendering, hydration, logs, and client components."
    },
    {
      "title": "Keep authorization server-side",
      "body": "Confirm browser controls do not substitute for a server decision about protected resources."
    }
  ],
  "outputs": [
    "Source-to-context map",
    "Message contract review",
    "Rendering control notes"
  ],
  "pitfalls": [
    "Treating client checks as access control",
    "Using generic sanitization without knowing the output context",
    "Trusting all same-window messages"
  ],
  "references": {
    "resources": [
      {
        "id": "owasp-browser-message-trust-boundaries",
        "title": "HTML5 Security Cheat Sheet: Web Messaging",
        "url": "https://vulns.co/research/resources/owasp-browser-message-trust-boundaries/"
      },
      {
        "id": "nextjs-server-client-data-security",
        "title": "Next.js data security: server authorization and client-visible data",
        "url": "https://vulns.co/research/resources/nextjs-server-client-data-security/"
      },
      {
        "id": "w3c-2026-trusted-types-policy-authority",
        "title": "Trusted Types: typed sinks depend on trustworthy policy creation",
        "url": "https://vulns.co/research/resources/w3c-2026-trusted-types-policy-authority/"
      }
    ],
    "diagrams": [
      {
        "id": "browser-message-authority-boundaries",
        "title": "Browser messages need separate trust checks",
        "url": "https://vulns.co/research/diagrams/browser-message-authority-boundaries/"
      },
      {
        "id": "server-client-data-consumer-boundaries",
        "title": "Server disclosure and browser interpretation",
        "url": "https://vulns.co/research/diagrams/server-client-data-consumer-boundaries/"
      }
    ],
    "reports": [
      {
        "id": "facebook-sdk-message-authentication-randomness-2023",
        "title": "Facebook SDK message authentication relied on insecure randomness",
        "url": "https://vulns.co/research/reports/facebook-sdk-message-authentication-randomness-2023/"
      },
      {
        "id": "meta-pixel-cross-window-authority-binding-2024",
        "title": "Meta Pixel cross-window handling lost message and token authority",
        "url": "https://vulns.co/research/reports/meta-pixel-cross-window-authority-binding-2024/"
      },
      {
        "id": "hackerone-report-json-serialization-data-exposure-2025",
        "title": "Framework serialization change exposed private HackerOne user attributes",
        "url": "https://vulns.co/research/reports/hackerone-report-json-serialization-data-exposure-2025/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/javascript/",
  "markdown_url": "https://vulns.co/skills/javascript/SKILL.md"
}
