The Runtime Theory
Browser Input Security

Treat Browser Input as Data at Every Boundary

Browser security depends on keeping untrusted data from becoming executable code or changing the meaning of a command.

The Runtime Theory Team5 min read#xss#input-validation#encoding
▸ On this page

The model

Browser security depends on keeping untrusted data from becoming executable code or changing the meaning of a command. Validation checks whether data fits an expected shape; context-aware output encoding ensures text is interpreted as text in HTML, an attribute, a URL, or JavaScript.

A concrete walk-through

If a comment is stored and later placed into a page, escaping it for the correct HTML context prevents markup from becoming active. A Content Security Policy can reduce some exploit paths, but it does not replace safe templating. Server-side validation remains necessary because clients can be bypassed.

Costs and failure cases

Input filtering by searching for a few dangerous strings is fragile because parsers accept many equivalent forms. SQL parameters, HTML output encoding, URL validation, and shell argument handling solve different boundary problems. Use the control designed for the interpreter that will consume the value.

Check your understanding

A search term is inserted into both an HTML heading and a query selector. Explain why one escaping function should not automatically be reused for both contexts.

Further reading

OWASP Cheat Sheet: Cross Site Scripting Prevention

Not started

Sign in to save your learning progress.

Sign in to save