Securing AngularJS applications


  • XSS 
  • Cross Site Request Forgery (CSRF) 
  • Single Origin Policy (SOP) 
  • Cross-Origin Resource Sharing (CORS) 
  • Token-based authentication

XSS (Cross-Site-Scripting)

What is XSS? 

  • Cross-Site-Scripting (XSS) means that an attacker can insert custom JavaScript code which is then displayed in the unsuspecting user's browser 
  • XSS is an enabler for more serious security attacks 
    • Phishing 
    • Session or authentication token stealing 
    • Sensitive data extraction

