OWASP Web Security Reference
Stack-agnostic stubs for web controls the Top 10 checklist does not cover in depth. Split out of OWASP Security Checklist on 2026-10-04. Expand to dedicated pages when targeted sources are ingested. Session Management: min 128-bit entropy tokens,HttpOnly, Secure, SameSite=Strict; invalidate on logout server-side; rotate on privilege change; never in URL parameters.
CSRF: synchronizer token pattern or SameSite=Strict cookies; verify Origin/Referer headers; custom request headers as secondary defense; exempt GET/HEAD/OPTIONS (must be idempotent).
DOM-Based XSS: untrusted sources include document.URL, location.hash, document.referrer, postMessage; dangerous sinks include raw HTML setters and eval; never pass untrusted source to dangerous sink without DOMPurify.
IDOR: validate authenticated user owns the requested resource; map internal IDs to per-user opaque tokens; log access denials; scope queries to user_id — never fetch by id alone.
Transaction Authorization: re-authenticate for high-value actions (account deletion, payment); idempotency keys for financial transactions; audit log of all state-changing operations with before/after values.
Third-Party Scripts: Subresource Integrity (SRI) for CDN-hosted scripts; CSP to allowlist script sources; audit third-party scripts for data exfiltration risk.
Deserialization: never deserialize untrusted data directly into objects; validate type before deserializing; use schema validation (zod, joi) on JSON.parse results; sign serialized tokens.
DoS: rate limit all public endpoints (especially auth, search, file upload); request size limits; avoid regex backtracking (ReDoS); connection timeouts.
Related Pages
- OWASP Security Checklist — hub: severity classification and the other OWASP pages
- OWASP Top 10 Checklist — the classic Top 10 review checklist