Device Bound Session Credentials (DBSC) for Node.js — middleware that binds session cookies to a hardware TPM key to stop cookie theft, with a Web Crypto polyfill for Firefox & Safari.
-
Updated
Jul 25, 2026 - TypeScript
Device Bound Session Credentials (DBSC) for Node.js — middleware that binds session cookies to a hardware TPM key to stop cookie theft, with a Web Crypto polyfill for Firefox & Safari.
🍪 Cookie Security Lab - A comprehensive CTF challenge demonstrating 6 cookie vulnerabilities with hands-on exploitation exercises, hashed flags, and secure patterns for learning.
Framework-neutral session binding for Node.js. Make stolen session cookies harder to reuse.
Darkly – hands-on examples of common web security vulnerabilities.
Hands-on browser security labs — SOP, CORS, CSP, SRI, Cookie flags & MitM attacks | Node.js
Captures and logs browser cookies for devs who need lightweight session debugging tools
Add a description, image, and links to the cookie-security topic page so that developers can more easily learn about it.
To associate your repository with the cookie-security topic, visit your repo's landing page and select "manage topics."