Networking, Browser Internals & Security
HTTP contracts, cache validation, DNS, TCP, TLS, HTTP versions, CORS, credentials, secure cookies, CSRF, CSP, service workers, storage partitioning, secure API boundaries, OAuth, OIDC, PKCE, token refresh, browser permissions, iframe isolation, postMessage, Web Crypto, realtime transports, secure uploads, download safety, COOP, COEP, CORP, supply-chain governance, patch operations, secrets boundaries, logging privacy, security testing, threat modeling, architecture review, incident response, privacy impact reviews, senior security answer structure, browser origin policy, sandboxing, trust boundaries, auth, storage, privacy, and attack surfaces.
Q016-Q027, Q251-Q280
Use this topic guide when you want to study by theme instead of reading the entire handbook in order.