Files
clean-architecture-frontend…/docs/security/browser-boundary.md

584 B

Browser security boundary

The browser bundle is public. Secrets, token lifecycle, raw HTML injection, dynamic code execution, untrusted script URLs, and public production source maps are prohibited defaults.

config/hosting/security-headers.json is the declared header set. Hosting verification compares that declaration with live responses. CSP deliberately omits unsafe-inline and unsafe-eval; production code and built assets must remain compatible with that baseline.

Route guards are UX hints and client validation does not replace backend authorization or validation.