前端安全新范式:2026年防护实战
前言
前端安全不再是后端的事...
XSS防护
Trusted Types
javascript
window.trustedTypes.createPolicy('myPolicy', {
createHTML: (string) => sanitizeHtml(string)
});
CSRF防护
SameSite Cookie
javascript
app.use(session({
cookie: {
sameSite: 'strict',
secure: true,
httpOnly: true
}
}));