{
"item_title" : "Secrets in the Browser",
"item_author" : [" Hemanth Gorijala "],
"item_description" : "Modern security programs scan repositories, pull requests, and pipelines for secrets. Those controls are necessary, but they answer only one question: is the source clean. They do not prove what the deployed application actually serves to a browser after it is built, configured, and running. Single-page applications, cloud-backed front ends, API gateways, runtime configuration, and source maps create paths where a credential appears only after source review. A build step can inline a secret into a JavaScript bundle. A runtime endpoint can serve it live. A source map can reveal it. In each case the repository is clean and the served application is not. Secrets in the Browser is a practitioner field guide to that gap. You will learn the five structural paths that deliver credentials to clients; why DAST scanners crawl the right files but do not classify credential-grade values inside JavaScript, JSON, XML, source maps, and API responses; how to inspect live traffic and classify public identifiers versus credential-grade values; step-by-step remediation using PKCE, the backend-for-frontend pattern, API gateways, managed identity, vaults, and CI/CD release gates; and how to scan source, build artifacts, and runtime. Written for application-security engineers, penetration testers, DevSecOps and platform engineers, frontend and full-stack developers, and the engineering leaders who set release standards. All examples are synthetic.",
"item_img_path" : "https://covers2.booksamillion.com/covers/bam/9/79/819/028/9798190281941_b.jpg",
"price_data" : {
"retail_price" : "29.99", "online_price" : "29.99", "our_price" : "29.99", "club_price" : "29.99", "savings_pct" : "0", "savings_amt" : "0.00", "club_savings_pct" : "0", "club_savings_amt" : "0.00", "discount_pct" : "10", "store_price" : ""
}
}
Secrets in the Browser : Detecting and Remediating Client-Side Credential Exposure
Overview
Modern security programs scan repositories, pull requests, and pipelines for secrets. Those controls are necessary, but they answer only one question: is the source clean. They do not prove what the deployed application actually serves to a browser after it is built, configured, and running.
Single-page applications, cloud-backed front ends, API gateways, runtime configuration, and source maps create paths where a credential appears only after source review. A build step can inline a secret into a JavaScript bundle. A runtime endpoint can serve it live. A source map can reveal it. In each case the repository is clean and the served application is not. Secrets in the Browser is a practitioner field guide to that gap. You will learn the five structural paths that deliver credentials to clients; why DAST scanners crawl the right files but do not classify credential-grade values inside JavaScript, JSON, XML, source maps, and API responses; how to inspect live traffic and classify public identifiers versus credential-grade values; step-by-step remediation using PKCE, the backend-for-frontend pattern, API gateways, managed identity, vaults, and CI/CD release gates; and how to scan source, build artifacts, and runtime. Written for application-security engineers, penetration testers, DevSecOps and platform engineers, frontend and full-stack developers, and the engineering leaders who set release standards. All examples are synthetic.This item is Non-Returnable
Customers Also Bought
Details
- ISBN-13: 9798190281941
- ISBN-10: 9798190281941
- Publisher: Independently Published
- Publish Date: August 2026
- Dimensions: 9 x 6 x 0.71 inches
- Shipping Weight: 1 pounds
- Page Count: 340
Related Categories
