Web Security
Enforce web security and avoid security vulnerabilities
Source: .agents/rules/web-security.mdc
Metadata
- name: web-security
- alwaysApply: true
Content
Web Security
We treat web security as a core requirement, not an afterthought. Assume hostile input and untrusted environments by default.
Core Principles
- NEVER trust user input
- ALWAYS validate and sanitize data at boundaries
- Prefer secure defaults over configurability
XSS & Injection
- AVOID
dangerouslySetInnerHTMLand raw HTML injection - Escape and encode dynamic content properly
- Never interpolate untrusted data into HTML, CSS, or JS contexts
- Ensure SQL injection protection
Authentication & Authorization
- Do not store secrets or tokens in insecure locations
- AVOID localStorage for sensitive credentials when possible
- Use HTTP-only, secure cookies where applicable
- Always enforce authorization on the server
- When consuming sensitive auth tokens from URL query params, preserve the existing auth/redirect flow first, set validated cookies on the outgoing response, and only then scrub sensitive params from the outgoing URL. Do not short-circuit route-specific middleware before it has made its normal access-control or redirect decision.
- Auth token URL cleanup changes must include regression tests for both cases:
- route middleware returns/rewrites/redirects and the outgoing
Locationis scrubbed; - route middleware continues to the page and a cleaned redirect is returned instead. Tests must also assert valid cookies are set before the cleanup redirect and unrelated query params are preserved.
- route middleware returns/rewrites/redirects and the outgoing
Browser Security APIs
- Respect CORS, CSP, and browser security boundaries
- Use Content Security Policy to restrict script and resource execution
- Avoid inline scripts and styles when CSP is enabled
Data Handling
- Minimize data exposure
- Do not log sensitive information
Dependencies & Supply Chain
- Avoid unnecessary packages
- Treat third-party code as untrusted input
General Principles
- Simplicity reduces attack surface
- If unsure, choose the more restrictive option