Zero-Trust Client Security
Client-side token storage in `localStorage` or `sessionStorage` is fundamentally vulnerable to Cross-Site Scripting (XSS) attacks. A single compromised npm dependency can silently exfiltrate stored tokens to external servers.
Our architecture enforces **Zero-Exposure Cookies**:
* Authentication tokens are stored exclusively in `HttpOnly`, `Secure`, `SameSite=Strict` cookies.
* JavaScript running in the browser cannot read or inspect cookie values via `document.cookie`.
* Sensitive session payloads are encrypted with AES-256-GCM before signing.
Timing-Safe Webhook Verification
All webhook payloads from payment processors and third-party integrations are validated using constant-time HMAC comparison to eliminate timing attacks:
verifySignature.ts
import crypto from 'crypto';
export function verifyWebhook(rawBody: string, signature: string, secret: string): boolean {
const expected = crypto.createHmac('sha256', secret).update(rawBody).digest('hex');
return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signature));
}