| Q256 | Cookies | Use HttpOnly, Secure, SameSite, narrow scope, server revocation, and clear logout semantics for session boundaries. |
| Q257 | CSRF | Protect cookie-authenticated mutations with honest methods, SameSite, tokens or origin checks, and server authorization. |
| Q258 | CSP | Start report-only, inventory sources, remove unsafe inline/eval paths, then enforce monitored directives. |
| Q259-Q260 | Client state | Treat service workers and storage as production security surfaces with versioning, cleanup, and privacy-aware assumptions. |