Security

Common web attacks, as listed by MDN, and how Sluurp handles each. Most need nothing from you.

Cross-site scripting (XSS)

Text is never parsed as markup. JSX and html templates insert strings as text, so a name like <img onerror=…> renders literally. javascript: URLs in href, src, action etc. are neutralised however they’re encoded. Strings can’t be event handlers: onclick="…" is rejected. The same applies to server rendering.

Cross-site request forgery (CSRF)

Requests are authenticated by the Authorization header, never by cookies. Another site can make the browser send a request but can’t add the header, so it arrives unauthenticated.

Clickjacking

HTML pages can’t be framed by other sites: all are sent with X-Frame-Options: SAMEORIGIN and frame-ancestors 'self'. A page meant for embedding can set its own header, which takes precedence.

Insecure direct object references (IDOR)

Ids are random, but that’s not the protection. Every read and write goes through the collection’s rules, enforced in SQL down to individual fields, so knowing an id grants nothing.

Manipulator in the middle (MITM)

Serve behind TLS; see Deploying. Once a browser connects over HTTPS, Strict-Transport-Security pins it there for a year.

Server-side request forgery (SSRF)

Outbound requests made on a user’s behalf (a function’s fetch, link previews) can only reach public addresses. Loopback, private ranges and cloud metadata endpoints are blocked, every redirect is re-checked, and the check applies to the resolved IP actually connected to, so DNS rebinding doesn’t bypass it. Superusers can allow-list extra hosts for functions.

Prototype pollution

The server parses JSON into Rust types, which have no prototype. In the browser, island props and RPC results are parsed with devalue, which rejects __proto__ keys.

Cross-site leaks

Cross-site referrers are trimmed to the origin (strict-origin-when-cross-origin), and MIME sniffing is disabled (nosniff).

Supply chain

Nothing is installed at runtime; the server is a single binary. Packages are vendored byte for byte into vendor/ and served from there, not a CDN, so what runs is exactly what you reviewed and committed.

Phishing and subdomain takeover

These are about people and DNS, not code. Offer two-factor sign-in (see Sign-in), and delete DNS records when their target server goes away.