Skip to main content

SID-HARD-05 — Browser Security Controls

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupSystem Hardening Controls

Description

React SPA with CSP headers, SRI (Subresource Integrity), SVG sanitization. WebCrypto API for all crypto operations (no JS crypto libraries). Standard browser security: same-origin policy, CORS enforcement.

Components

  • Wallet Frontend

Source References

Audit Findings

FindingSeverityStatus
EN-P-7 — Partial hardening and error handlingmediumresolved
ISO-T-5 — Partial endpoint and privileged access controlsmediumopen
ISO-T-6 — Partial vulnerability and malware protectionmediumopen
ISO-T-9 — Partial data leakage preventionlowopen