WeAreDevelopers LIVE Dec 1, 2020

A Primer in Single Page Application Security (Angular, React, Vue.js)

Thomas Konrad

Are your React, Vue, or Angular apps safe from DOM-based XSS? Master defense-in-depth strategies like CSP and Trusted Types to secure your single-page applications.

Pause
Mute Enter Fullscreen
#1 about 4 min

Overview of single page application architecture

Single page applications improve speed and separation of concerns compared to traditional server-rendered websites.

#2 about 5 min

Dealing with cross-site scripting in single page applications

Cross-site scripting remains the primary security vulnerability when mixing untrusted data with HTML markup.

#3 about 3 min

Comparing framework defenses for inner HTML manipulation

Angular automatically sanitizes inner HTML inputs whereas React and Vue require manual verification of trusted sources.

#4 about 4 min

Securing link attributes and other hazardous DOM sinks

Attributes like horizontal references or dynamic script tags can execute arbitrary JavaScript if supplied with malicious URLs.

#5 about 4 min

Implementing manual sanitization using the DOMPurify library

Frameworks without built-in strict sanitizers enforce the usage of external libraries like DOMPurify to clean HTML inputs.

#6 about 3 min

Avoiding direct DOM manipulation and insecure functions

Bypassing framework templates to directly invoke raw document functions or evaluators reintroduces critical injection vulnerabilities.

#7 about 4 min

Implementing content security policies for single page applications

Content security policies add an effective secondary defense layer by blocking unauthorized origins and inline scripts.

#8 about 3 min

Enforcing strict DOM APIs using trusted types

The trusted types directive restricts insecure string assignments to DOM sinks by mandating strongly typed secure objects.

#9 about 4 min

Security checklist and best practices for interface development

Following framework standards alongside linters and robust policies mitigates the vast majority of injection risks.

#10 about 3 min

Automating security checks for third-party module dependencies

Continuous automated scanning of package repositories manages the broad attack surface introduced by external libraries.

#11 about 4 min

Applying transport restrictions and cookie security flags

Strict transport security protocols and verified cross-origin configurations solidify the foundational protection of the application backend.

Matching moments

1:44 min

Evaluating framework architectures against cross-site scripting attack vectors

Philippe De Ryck · LIVE

1:35 min

Enhancing core browser security with the native HTML Sanitizer API

Chris Heilmann +2 · LIVE

1:05 min

Handling modern injection flaws and cross-site scripting

Christian Wenz Christian Wenz · WWC Europe 2026

2:07 min

Understanding classic XSS risks in reactive frontend frameworks

Ramona Schwering Ramona Schwering · WWC Europe 2026

1:55 min

Demonstrating cross-site scripting in an Angular application

martinakraus martinakraus · WWC 2024

2:10 min

Analyzing the out-of-the-box security posture of Vue.js

Philippe De Ryck · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Architecting AI in Angular: WebMCP, A2UI, and the Agent Experience

Ankita Sood

Sr. Principal Engineer @ Secureworks | Angular GDE

Ankita Sood
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey