Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Open Web Docs

@openwebdocs@front-end.social
mastodon 4.7.3
  • Open on front-end.social

Open Web Docs supports web platform documentation for the benefit of web developers & designers worldwide.

0 Followers
0 Following
14 Posts
Joined November 11, 2022
Website:
https://openwebdocs.org
GitHub:
https://github.com/openwebdocs
Donate:
https://opencollective.com/open-web-docs
Bluesky:
https://bsky.app/profile/openwebdocs.org
Open post
Open Web Docs @openwebdocs@front-end.social
· 3mo ago

We've completed our work on Web Security documentation on @mdn@mastodon.social !

The entire MDN content tree has been reworked and now features in-depth information on:

  • Attacks
  • Defenses
  • Authentication
  • Threat Modeling

↪️ Blog post https://openwebdocs.org/content/posts/security-docs-sovereign-tech-agency/

openwebdocs.org
70
0
56
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 8mo ago

We've written a new guide on Passkeys!

Passkeys address many of the most serious weaknesses of other authentication methods.

In this guide we will:
- Introduce you to the WebAuthn API
- Go through registration and sign-in flows
- Give an overview of the security properties of passkeys
- Provide you with guidance on managing passkeys as well as migrating from passwords.

https://developer.mozilla.org/en-US/docs/Web/Security/Authentication/Passkeys

Thanks to Hamish Willee and Simone Onofri for providing reviews.

developer.mozilla.org
24
0
17
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 5mo ago

We've written new MDN security docs on Threat Modeling and provided an example threat model for a (simplified) blog website.

Threat modeling is a form of risk assessment in which you create a representation of a system so you can identify relevant security and privacy concerns, understand what can go wrong, and decide how to respond.

Many thanks to Hamish Willee and Simone Onofri (@w3cdevs@w3c.social) for your input and reviews!

https://developer.mozilla.org/en-US/docs/Web/Security/Threat_modeling

developer.mozilla.org
11
0
8
1
Open post
Open Web Docs @openwebdocs@front-end.social
· 7mo ago

We've written a new guide on Session Management!

Once you authenticated your users, you will need to manage their sessions.

This guide walks you through two different architectures for session management (cookies and JWTs) and describes common session attacks to watch out for.

For now, this is the final article in our series on authentication on the Web :)

https://developer.mozilla.org/en-US/docs/Web/Security/Authentication/Session_management

developer.mozilla.org
16
1
11
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 8mo ago

Do you delegate web security to security specialists or are you responsible yourself for implementing web security features and practices?

The W3C SWAG CG survey asks this and other questions and we would value your input as we create Web Security documentation.

https://docs.google.com/forms/d/e/1FAIpQLScbKJL2Q8XABAHVystmqGU2lQoE0tAJSL_dwhvwPwBcJ-M4fQ/viewform?usp=header

docs.google.com
16
2
18
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 8mo ago

Open Web Docs 2025 Report

We're reflecting on our fifth year of ensuring the long-term health of web platform documentation.

Happy 5-year anniversary to us! 🍰
Thanks to the many individuals and organizations for your support on our journey! 💜

https://openwebdocs.org/content/reports/2025/

openwebdocs.org
13
0
11
1
Open post
Open Web Docs @openwebdocs@front-end.social
· 6mo ago

We've written a new guide on Fetch Metadata!

Fetch metadata is a group of HTTP request headers.

They tell you if requests are navigation between documents, request for a subresource, or requests made from JavaScript, and whether they are same-origin, or same-site, or from completely different sites.

Thanks to this information, you can implement defenses against cross-origin attacks such as cross-site request forgeries (CSRF) and various cross-site leaks.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Fetch_metadata

developer.mozilla.org
6
0
4
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 10mo ago

RE: @patrickbrosset@mas.to

In 2025, we systematically collected compat data for 28 browser releases:

Firefox 135 - 147
Chrome 133 - 144
Safari 18.4, 26, 26.2

We're keeping your compat tables up-to-date.

mas.to
13
0
6
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 5mo ago

We've updated MDN's guide on Subresource Integrity (SRI) and added docs for the HTML `integrity` attribute.

The SRI docs now talk about the fact that you can provide multiple `integrity` values (using the same or different hash functions) and how browsers will handle that.

Thanks to @codingjoe@fosstodon.org for your feedback! We're looking forward to improved SRI support in @django@fosstodon.org!

https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Subresource_Integrity

Subresource Integrity - Security | MDN
MDN Web Docs

Subresource Integrity - Security | MDN

Subresource Integrity (SRI) is a security feature that enables browsers to verify that resources they fetch (for example, from a CDN) are delivered without unexpected manipulation. It works by allowing you to provide a cryptographic hash that a fetched resource must match.

4
2
5
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 10mo ago

We've written a new guide on Federated Identity (FedCM).

The articles helps you to understand what's happening under the surface when a website works with an identity provider (IdP) to add federated sign-in for their users.

We cover the main flows as defined in the OpenID Connect (OIDC) protocol and its security features.
We also present how the FedCM API helps with moving away from third party cookies, and we list some strengths and weaknesses of Federated Identity.

https://developer.mozilla.org/en-US/docs/Web/Security/Authentication/Federated_identity

developer.mozilla.org
11
0
10
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 6mo ago

RE: @floscholz@front-end.social

Catch Daniel and Florian at @FOSSBackstage@floss.social today and tomorrow!

front-end.social
5
0
4
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 7mo ago

Hey @niklasmerz@w3c.social, thank you so much for your kind donation to Open Web Docs! 💜

It's always a pleasure talking to you about WebViews and figuring out compat data for https://caniwebview.com/

Everyone, join the W3C WebView CG to be part of WebView conversations: https://www.w3.org/groups/cg/webview/

caniwebview.com
4
0
4
1
Open post
Open Web Docs @openwebdocs@front-end.social
· 7mo ago

Thanks to 108 of you who responded to the W3C SWAG CG survey on web security features!

77% said they are responsible themselves for implementing web security features and practices. 23% delegate this work to security specialists.

Wondering: Do you delegate risk analysis work, like Threat Modeling, to security specialists, or do you do that yourself, too?

3
0
2
0
Open post
Open Web Docs @openwebdocs@front-end.social
· 8mo ago
Replying to
@dletorey 💜 💜 💜
1
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:21:53 UTC