Our task for this static site project was to create a seamless and secure user experience, emphasizing data protection and user privacy. However, we encountered challenges related to security and data encryption. The absence of CORS (Cross-Origin Resource Sharing) and JS - Secure Cookies left potential vulnerabilities, compromising the confidentiality of user data.
Additionally, without HTML - Content Security Policy (CSP), the site lacked protection against certain types of cyber attacks, leaving it vulnerable to security threats.
To address security concerns, we implemented CORS (Cross-Origin Resource Sharing) to control resource access and protect against unauthorized cross-origin requests. This strategic approach bolstered the site's security measures, ensuring the confidentiality of user data.
Simultaneously, we focused on user data protection by implementing JS - Secure Cookies. This involved using secure attributes for cookies to prevent potential security risks, enhancing the overall security of user data.
Furthermore, to fortify the site against cyber threats, we introduced HTML - Content Security Policy (CSP). This security feature allowed us to mitigate the risk of certain types of attacks, providing an additional layer of protection for user data and enhancing the overall security posture of the static site.