menu
{ "item_title" : "Secrets in the Browser", "item_author" : [" Hemanth Gorijala "], "item_description" : "Modern security programs scan repositories, pull requests, and pipelines for secrets. Those controls are necessary, but they answer only one question: is the source clean. They do not prove what the deployed application actually serves to a browser after it is built, configured, and running. Single-page applications, cloud-backed front ends, API gateways, runtime configuration, and source maps create paths where a credential appears only after source review. A build step can inline a secret into a JavaScript bundle. A runtime endpoint can serve it live. A source map can reveal it. In each case the repository is clean and the served application is not. Secrets in the Browser is a practitioner field guide to that gap. You will learn the five structural paths that deliver credentials to clients; why DAST scanners crawl the right files but do not classify credential-grade values inside JavaScript, JSON, XML, source maps, and API responses; how to inspect live traffic and classify public identifiers versus credential-grade values; step-by-step remediation using PKCE, the backend-for-frontend pattern, API gateways, managed identity, vaults, and CI/CD release gates; and how to scan source, build artifacts, and runtime. Written for application-security engineers, penetration testers, DevSecOps and platform engineers, frontend and full-stack developers, and the engineering leaders who set release standards. All examples are synthetic.", "item_img_path" : "https://covers2.booksamillion.com/covers/bam/9/79/819/028/9798190281941_b.jpg", "price_data" : { "retail_price" : "29.99", "online_price" : "29.99", "our_price" : "29.99", "club_price" : "29.99", "savings_pct" : "0", "savings_amt" : "0.00", "club_savings_pct" : "0", "club_savings_amt" : "0.00", "discount_pct" : "10", "store_price" : "" } }
Secrets in the Browser|Hemanth Gorijala

Secrets in the Browser : Detecting and Remediating Client-Side Credential Exposure

local_shippingShip to Me
In Stock.
FREE Shipping for Club Members help

Overview

Modern security programs scan repositories, pull requests, and pipelines for secrets. Those controls are necessary, but they answer only one question: is the source clean. They do not prove what the deployed application actually serves to a browser after it is built, configured, and running.

Single-page applications, cloud-backed front ends, API gateways, runtime configuration, and source maps create paths where a credential appears only after source review. A build step can inline a secret into a JavaScript bundle. A runtime endpoint can serve it live. A source map can reveal it. In each case the repository is clean and the served application is not.

Secrets in the Browser is a practitioner field guide to that gap. You will learn the five structural paths that deliver credentials to clients; why DAST scanners crawl the right files but do not classify credential-grade values inside JavaScript, JSON, XML, source maps, and API responses; how to inspect live traffic and classify public identifiers versus credential-grade values; step-by-step remediation using PKCE, the backend-for-frontend pattern, API gateways, managed identity, vaults, and CI/CD release gates; and how to scan source, build artifacts, and runtime.

Written for application-security engineers, penetration testers, DevSecOps and platform engineers, frontend and full-stack developers, and the engineering leaders who set release standards. All examples are synthetic.

This item is Non-Returnable

Details

  • ISBN-13: 9798190281941
  • ISBN-10: 9798190281941
  • Publisher: Independently Published
  • Publish Date: August 2026
  • Dimensions: 9 x 6 x 0.71 inches
  • Shipping Weight: 1 pounds
  • Page Count: 340

Related Categories

You May Also Like...

    1

BAM Customer Reviews