All Posts

Zero-Exposure Auth: AES-256 Session Sealing & Defense-in-Depth against Token Exfiltration

Protecting client identities with HttpOnly SameSite=Strict cookies, AES-256-GCM payload encryption, and HMAC payment signature verification.

Zero-Trust Client Security

Client-side token storage in `localStorage` or `sessionStorage` is fundamentally vulnerable to Cross-Site Scripting (XSS) attacks. A single compromised npm dependency can silently exfiltrate stored tokens to external servers. Our architecture enforces **Zero-Exposure Cookies**: * Authentication tokens are stored exclusively in `HttpOnly`, `Secure`, `SameSite=Strict` cookies. * JavaScript running in the browser cannot read or inspect cookie values via `document.cookie`. * Sensitive session payloads are encrypted with AES-256-GCM before signing.

Timing-Safe Webhook Verification

All webhook payloads from payment processors and third-party integrations are validated using constant-time HMAC comparison to eliminate timing attacks:
verifySignature.ts
import crypto from 'crypto';

export function verifyWebhook(rawBody: string, signature: string, secret: string): boolean {
  const expected = crypto.createHmac('sha256', secret).update(rawBody).digest('hex');
  return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signature));
}
✓