← Explore learning paths

For web developers

Web Security: The Modern Browser Model

Understand browser security boundaries, cross-origin requests, cookies, and the policies that protect web applications.

25 lessons ready to readFree to readLearn at your own pace
Read the first lesson → My progress in this path →
01 / READ

Start with a lesson that meets you where you are.

02 / PRACTICE

Try questions to check what you understand.

03 / RETURN

Sign in to keep your practice progress together.

Your learning path

25 of 42 topics have lessons available today. Choose any available lesson.

  1. 01

    Browser Security Foundations

    Read the lesson, then try the practice.

  2. 02

    Same-Origin Policy Deep Dive

    Read the lesson, then try the practice.

  3. 03

    Cross-Origin Read Blocking

    Read the lesson, then try the practice.

  4. 04

    HTTPS and Transport Security

    Read the lesson, then try the practice.

  5. 05

    Cross-Origin Resource Sharing (CORS)

    Read the lesson, then try the practice.

  6. 06

    CORS Protocol Mechanics

    Read the lesson, then try the practice.

  7. 07

    Simple vs Preflighted Requests

    Read the lesson, then try the practice.

  8. 08

    CORS Credentials and Cookies

    Read the lesson, then try the practice.

  9. 09

    Resource Isolation Policies

    Read the lesson, then try the practice.

  10. 10

    Cross-Origin Resource Policy

    Read the lesson, then try the practice.

  11. 11

    Cross-Origin Embedder Policy

    Read the lesson, then try the practice.

  12. 12

    Spectre Mitigation Context

    Read the lesson, then try the practice.

  13. 13

    Content Security Policy (CSP)

    Read the lesson, then try the practice.

  14. 14

    CSP Directive Architecture

    Read the lesson, then try the practice.

  15. 15

    CSP Levels and Evolution

    Read the lesson, then try the practice.

  16. 16

    CSP Reporting and Monitoring

    Read the lesson, then try the practice.

  17. 17

    Trusted Types for DOM XSS

    Read the lesson, then try the practice.

  18. 18

    Cookie Security and Partitioning

    Read the lesson, then try the practice.

  19. 19

    SameSite Cookie Attribute

    Read the lesson, then try the practice.

  20. 20

    Cookie Prefixes and Partitioning

    Read the lesson, then try the practice.

  21. 21

    Secure and Host Cookie Prefixes

    Read the lesson, then try the practice.

  22. 22

    Partitioned Cookies (CHIPS)

    Read the lesson, then try the practice.

  23. 23

    Third-Party Cookie Deprecation

    Read the lesson, then try the practice.

  24. 24

    Permissions and Feature Policy

    Read the lesson, then try the practice.

  25. 25

    Permissions-Policy Directives

    Read the lesson, then try the practice.

Topics without lessons yet

These are part of the outline. Lessons are not available for them yet.

  • Origin Definition and Matching
  • SOP Exceptions and Pitfalls
  • HTTPS Misconceptions
  • HSTS and Certificate Pinning
  • Mixed Content Vulnerabilities
  • CORS Security Anti-patterns
  • SharedArrayBuffer Security Model
  • Strict CSP Implementation
  • Trusted Types API Fundamentals
  • DOM XSS Attack Vectors
  • Migration to Trusted Types
  • CSRF Protection with SameSite
  • SameSite Default Behavior
  • Top-Level Navigation Exceptions
  • Feature Policy Allowlists
  • Iframe Feature Delegation
  • Permission Policy Use Cases