$less ~/slides/modern-security-features-for-web-apps
// deck 04 · SecAppDev
Modern Security Features
for web applications
1 / 75
skip thumbnails
// key slides
// what you take away
- Allowlist CSPs fail: tools bypass more than 95% of them automatically.
- 100+ Google apps enforce nonce CSP plus Trusted Types and had no XSS in 2021.
- Fetch Metadata lets the server reject cross-site requests in a few lines.






























































![Slide 63: CSP Coverage at Google [2019]](/assets/slides/modern-security-features-for-web-apps/063.webp)
![Slide 64: CSP Coverage at Google [2023]](/assets/slides/modern-security-features-for-web-apps/064.webp)





















































































