For web developers
Web Security: The Modern Browser Model
Understand browser security boundaries, cross-origin requests, cookies, and the policies that protect web applications.
Start with a lesson that meets you where you are.
Try questions to check what you understand.
Sign in to keep your practice progress together.
Your learning path
25 of 42 topics have lessons available today. Choose any available lesson.
- 01
Browser Security Foundations
Read the lesson, then try the practice.
- 02
Same-Origin Policy Deep Dive
Read the lesson, then try the practice.
- 03
Cross-Origin Read Blocking
Read the lesson, then try the practice.
- 04
HTTPS and Transport Security
Read the lesson, then try the practice.
- 05
Cross-Origin Resource Sharing (CORS)
Read the lesson, then try the practice.
- 06
CORS Protocol Mechanics
Read the lesson, then try the practice.
- 07
Simple vs Preflighted Requests
Read the lesson, then try the practice.
- 08
CORS Credentials and Cookies
Read the lesson, then try the practice.
- 09
Resource Isolation Policies
Read the lesson, then try the practice.
- 10
Cross-Origin Resource Policy
Read the lesson, then try the practice.
- 11
Cross-Origin Embedder Policy
Read the lesson, then try the practice.
- 12
Spectre Mitigation Context
Read the lesson, then try the practice.
- 13
Content Security Policy (CSP)
Read the lesson, then try the practice.
- 14
CSP Directive Architecture
Read the lesson, then try the practice.
- 15
CSP Levels and Evolution
Read the lesson, then try the practice.
- 16
CSP Reporting and Monitoring
Read the lesson, then try the practice.
- 17
Trusted Types for DOM XSS
Read the lesson, then try the practice.
- 18
Cookie Security and Partitioning
Read the lesson, then try the practice.
- 19
SameSite Cookie Attribute
Read the lesson, then try the practice.
- 20
Cookie Prefixes and Partitioning
Read the lesson, then try the practice.
- 21
Secure and Host Cookie Prefixes
Read the lesson, then try the practice.
- 22
Partitioned Cookies (CHIPS)
Read the lesson, then try the practice.
- 23
Third-Party Cookie Deprecation
Read the lesson, then try the practice.
- 24
Permissions and Feature Policy
Read the lesson, then try the practice.
- 25
Permissions-Policy Directives
Read the lesson, then try the practice.
Topics without lessons yet
These are part of the outline. Lessons are not available for them yet.
- Origin Definition and Matching
- SOP Exceptions and Pitfalls
- HTTPS Misconceptions
- HSTS and Certificate Pinning
- Mixed Content Vulnerabilities
- CORS Security Anti-patterns
- SharedArrayBuffer Security Model
- Strict CSP Implementation
- Trusted Types API Fundamentals
- DOM XSS Attack Vectors
- Migration to Trusted Types
- CSRF Protection with SameSite
- SameSite Default Behavior
- Top-Level Navigation Exceptions
- Feature Policy Allowlists
- Iframe Feature Delegation
- Permission Policy Use Cases