Skip to main content

Build secure software and web applications

Move from security requirements through safe implementation, browser boundaries, authorization tests, and vulnerability response.

Learning outcomes

  • Derive testable application security requirements from protection needs and abuse cases.
  • Keep untrusted data separate from interpreters, paths, browser code, and executable object graphs.
  • Design browser, server-side fetch, object authorization, concurrency, and safe-failure boundaries.
  • Verify the deployed application and manage vulnerabilities through remediation and learning.

Scenario

A multi-tenant administration application accepts browser and API requests, generates reports, imports remote data, stores uploaded files, and triggers asynchronous workers. The team must protect each path without assuming route authentication makes the application safe.

Ordered learning units

  1. Concept

    Vulnerability and Exploit

    Distinguish a software weakness, exploitable vulnerability, exploit path, exposure, and resulting security impact.

  2. Concept

    Canonicalization

    Convert equivalent input representations to one defined form before comparison, validation, authorization, and storage.

  3. Concept

    Injection

    Prevent attacker-controlled data from changing the structure or meaning of a command sent to an interpreter.

  4. Concept

    SQL Injection

    Keep untrusted values separate from SQL structure with parameterized queries, allowlisted identifiers, and narrow database authority.

  5. Concept

    Command Injection

    Avoid command interpreters and pass fixed executables and validated arguments through structured process APIs with narrow authority.

  6. Concept

    Same-Origin Policy

    Understand how scheme, host, and port define a browser origin and limit cross-origin reads, script access, and storage.

  7. Concept

    Cross-Site Scripting (XSS)

    Prevent untrusted data from executing as active browser content through context-aware encoding, safe DOM APIs, and constrained markup.

  8. Guide

    Secure browser origin boundaries

    Design origins, sessions, cross-origin reads, state changes, frames, messages, and scripts as separate browser security controls.

  9. Concept

    Server-Side Request Forgery (SSRF)

    Prevent untrusted input from making a server reach internal services, cloud metadata, local files, or other unapproved destinations.

  10. Concept

    Path Traversal

    Prevent attacker-controlled file names and paths from escaping an approved storage root after decoding and canonical resolution.

  11. Concept

    File Upload Security

    Validate, transform, store, scan, and serve untrusted files through bounded stages with separate names, origins, and authority.

  12. Concept

    Unsafe Deserialization

    Treat serialized objects as untrusted data and prevent input from selecting executable types, constructors, hooks, or object graphs.

  13. Concept

    Race Condition and TOCTOU

    Prevent security decisions from becoming stale before the protected state change, resource use, or authorization commit completes.

  14. Concept

    HTTP Request Smuggling

    Prevent HTTP intermediaries from disagreeing about message boundaries, request length, transfer coding, and the start of the next request.

  15. Concept

    Business Logic Abuse

    Protect workflow order, object state, quotas, prices, approvals, and other business invariants from valid-looking misuse.

  16. Guide

    Test application authorization

    Verify object, property, action, workflow, tenant, and administrative authorization with a systematic identity and state matrix.

  17. Concept

    Secure Error Handling

    Fail safely without bypassing controls, exposing sensitive internals, duplicating effects, or leaving partial security state.

  18. Concept

    Security Misconfiguration

    Prevent unsafe defaults, unnecessary features, exposed diagnostics, excessive authority, and configuration drift across environments.

  19. Concept

    Memory Safety

    Prevent spatial, temporal, initialization, and type-safety errors that can corrupt memory, disclose data, or redirect control flow.

Evaluation questions

  • Can you state the security requirement and final protected result for every control in one real feature?
  • Can untrusted data become structure in any database, process, path, template, browser, parser, or queue boundary?
  • Do route, object, property, action, workflow, transaction, and tenant decisions remain separate and testable?
  • Does the system preserve its invariants during concurrency, dependency failure, retry, rollback, and recovery?

Completion conditions

  • Build and review a threat and requirement model for one deployed application feature.
  • Run negative tests for injection, browser intent, cross-origin reads, server-side fetch, object authorization, file handling, concurrency, and direct-origin bypass.
  • Produce evidence for the deployed artifact, configuration, final state, vulnerability response owner, and residual risk.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo