Security wing
Where browser-only security goes to learn humility.
Client-side checks
Admin buttons are not bodyguards.
0/4 scenarios fixedStart run
Passwords
Encoding is not a vault.
0/5 scenarios fixedUnlock this door
Sessions
Convenience should still expire.
0/5 scenarios fixedUnlock this door
XSS
Strangers should not run JavaScript in your users' tabs.
0/4 scenarios fixedUnlock this door
CSRF
Another site should not act as your logged-in user.
0/3 scenarios fixedUnlock this door