惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
S
SegmentFault 最新的问题
V
Visual Studio Blog
J
Java Code Geeks
宝玉的分享
宝玉的分享
美团技术团队
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
有赞技术团队
有赞技术团队
量子位
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
博客园 - 叶小钗
月光博客
月光博客
P
Proofpoint News Feed
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
博客园_首页
腾讯CDC
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog

Syntax - Tasty Web Development Treats

Diffs, Trees, and VS Code 2.0 - Syntax #1008 8 Tech Choices to Lock In Before Agentmaxxing - Syntax #1007 Can AI Make Good Design? - Syntax #1006 Programatic and Skill based Video Creation with Remotion - Syntax #1005 TanHacked - Syntax #1004 Skills Skills Skills - Syntax #1003 The Real Pricing of LLMs - Syntax #1002 Managing Deadlines + Stress - Syntax #1001 Syntax Episode 1,000! - Syntax #1000 Writing Maintainable CSS - Syntax #999 How to Fix Vibe Coding - Syntax #998 Rating and Roasting Your Projects - Syntax #997 10 New CSS and HTML APIs - Syntax #996 Next.js Vendor Lock-in No More - Syntax #995 AI Sucks At CSS - Syntax #994 It’s Been A Hell Of Week - Syntax #993 Migrating Legacy Code Just Got Easier - Syntax #992 Vite’s bet on Cloudflare (VOID Framework) - Syntax #991 Vite Is Taking Over (Vite+) - Syntax #990 State of JS 2025 - Syntax #989 Cloudflare’s Next.js Slop Fork - Syntax #988 Remote Coding Agents - Syntax #987 Does Code Quality Matter Anymore? - Syntax #986 Stop putting secrets in .env - Syntax #985 How to Make a DOM Library Render Anything w/ Paolo Ricciuti - Syntax #984 Why I Chose Electron Over Native (And I’d Do It Again) - Syntax #983 Bots Are Ruining the Internet - Syntax #982 Browsers Are Finally Catching Up (Interop 2026) - Syntax #981 AI Coding Explained - Syntax #980 WebMCP: New Standard to Expose Your Apps to AI - Syntax #979
Client side security, XSS attacks & CSP with Stripe’s Ale...
2024-02-16 · via Syntax - Tasty Web Development Treats

Scott and Wes are joined by security expert, Alex Sexton of Stripe to cover all things: client security, XSS, attack vectors, and CSP (content security policy).

Show Notes

  • 00:00 Welcome to Syntax!
  • 00:31 Brought to you by Sentry.io.
  • 00:57 Who is Alex Sexton?
  • 04:44 Stripe dashboard is a work of art.
  • 05:08 Tell us about the design system.
  • React Aria
  • 08:59 Who develops the iOS app?
  • 09:50 Stripe's CSP (content security policy).
  • 12:50 What even is a content security policy?
  • Content Security Policy explanation
  • 13:57 Douglas Crockford of Yahoo on security.
  • Douglas on GitHub
  • 15:13 Security philosophy.
  • 16:59 What about inline styles and inline JavaScript?
  • 19:41 How do we safely set inline styles from JS?
  • 20:20 Setting up with meta tags.
  • 22:52 What are common situations that require security exceptions?
  • 26:24 Potential damage with inline style tags.
  • 32:45 Looping vulnerabilities.
  • 36:32 What about JavaScript injection?
  • 37:09 Myspace Samy Worm.
  • Myspace Samy Worm Wiki
  • Sentry.io Security Policy Reporting
  • 42:02 Does a CSP stop code from running in the console?
  • 43:28 What are some general security best practices?
  • 46:35 Strategies for rolling out a CSP.
  • 51:49 Final tip, Strict Dynamic.
  • Strict Dynamic
  • 56:36 Where does the CSP live within Stripe?
  • Original Black Friday story
  • 59:35 One last story.
  • 01:01:20 Sick Picks + Shameless Plugs

Sick Picks + Shameless Plugs

Hit us up on Socials!

Syntax: X Instagram Tiktok LinkedIn Threads

Wes: X Instagram Tiktok LinkedIn Threads

Scott:X Instagram Tiktok LinkedIn Threads

Randy: X Instagram YouTube Threads