WeAreDevelopers LIVE • Feb 24, 2022

Securing Frontend Applications with Trusted Types

Philippe De Ryck

Stop trusting static analysis to catch elusive DOM-based XSS. Move protection directly to the browser with Trusted Types to neutralize risky bypasses and unpatched third-party vulnerabilities forever.

Pause
Mute Enter Fullscreen
#1 about 4 min

The impact of cross-site scripting in modern web applications

How injected malicious code extracts sensitive data and executes dangerous operations.

#2 about 5 min

Rendering untrusted HTML and bypassing framework escaping protections

Bypassing default framework escaping with properties like innerHTML enables cross-site scripting attacks.

#3 about 3 min

Sanitizing untrusted inputs with external libraries and default behaviors

Removing dangerous elements from HTML output prevents malicious code execution in browser sinks.

#4 about 4 min

Accidental vulnerabilities generated by missing sanitization or element references

Directly accessing native DOM properties circumvents framework protections and introduces security flaws.

#5 about 7 min

Enforcing secure assignments using trusted types and response headers

Modifying default browser behavior blocks unsafe string assignments to dangerous HTML sinks.

#6 about 4 min

Improving code security with trusted types in development environments

Catching and fixing improper DOM assignments during local development secures applications globally.

#7 about 7 min

Securing third-party dependencies with default trusted types policies

Defining a fallback sanitization policy automatically protects applications from vulnerable external packages.

#8 about 3 min

Analyzing the out-of-the-box security posture of Vue.js

The Vue.js framework provides generic output escaping but lacks automatic sanitization for raw HTML insertion.

#9 about 2 min

Contrasting server-side validation against frontend injection responsibilities

Preventing DOM-based cross-site scripting relies entirely on secure client-side code rather than API endpoints.

#10 about 2 min

Preventing attackers from creating or injecting malicious trusted types

Locking down trusted type generation blocks third-party scripts from bypassing sanitization policies.

#11 about 2 min

Handling trusted type fallbacks in unsupported web browsers

Applications maintain basic sanitization protection levels even when running in environments lacking trusted types.

#12 about 3 min

Standardizing safe markup with an upcoming native sanitization API

Future browser capabilities will expose built-in HTML sanitizers to reduce dependency on external libraries.

#13 about 2 min

Evaluating framework architectures against cross-site scripting attack vectors

Moving away from runtime template parsing blocks common attack strategies across modern web platforms.

#14 about 2 min

Evaluating the feasibility of replacing the legacy DOM API

Maintaining backwards compatibility restricts complete structural overhauls of dangerous browser operations.

Matching moments

1:44 min

Enforcing safe HTML assignments using Trusted Types policies

martinakraus martinakraus · World Congress 2024

2:20 min

Enforcing strict DOM APIs using trusted types

Thomas Konrad · LIVE

1:35 min

Enhancing core browser security with the native HTML Sanitizer API

Chris Heilmann Chris Heilmann +2 · LIVE

3:37 min

Generating Trusted Types safely using the DOMPurify library

martinakraus martinakraus · World Congress 2024

1:43 min

Stopping cross-site scripting attacks via secure HTML types

Michael Koppmann · LIVE

3:07 min

Implementing zero trust security practices in frontend applications

Jan Peer Stöcklmair Jan Peer Stöcklmair · World Congress 2026 Europe