A public notebook for how I think: product judgment, craft, systems, and what I learn while shipping.
How XSS reaches the DOM, which browser APIs are sinks, and mitigations that hold in production—sanitization, CSP, cookies, and CSRF pairing.