Q261-Q265

Revision Sheet

API Boundaries

Frontend APIs must enforce authorization, object ownership, validation, safe mutations, privacy-aware responses, and observable errors server-side.

Auth Flows

OIDC login and token renewal need state, nonce, PKCE, safe callback handling, refresh deduplication, and clear expired-session UX.

Browser Trust

Permissions, iframes, sandboxing, and postMessage are trust negotiations that require explicit scope and runtime validation.