Revision Sheet
API Boundaries
Frontend APIs must enforce authorization, object ownership, validation, safe mutations, privacy-aware responses, and observable errors server-side.
Auth Flows
OIDC login and token renewal need state, nonce, PKCE, safe callback handling, refresh deduplication, and clear expired-session UX.
Browser Trust
Permissions, iframes, sandboxing, and postMessage are trust negotiations that require explicit scope and runtime validation.