Skip to main content
Engineering note

Browser authentication boundary

A concise reference for keeping session credentials outside browser JavaScript.

  • Security
  • Authentication

Boundary

Keep access and refresh credentials in Secure, HttpOnly cookies. Browser JavaScript should receive user and session metadata, not bearer credentials.

State changes

  • Allow only known browser origins.
  • Require a signed CSRF value for authenticated state changes.
  • Rotate refresh credentials atomically and treat replay as a session-family compromise.
  • Clear cookies and revoke server-side session state during logout.