What does modern web security mean for JavaScript developers in 2026, and where should we begin when securing a new application?

Recorded during the GDE Europe Summit 2026 in Berlin, this episode opens our new podcast series dedicated to JavaScript security.

Dariusz Kalbarczyk, co-founder of NG Poland, JS Poland, and AI Poland, talks with Jakub Andrzejewski, Senior Frontend Engineer at Storyblok, Google Developer Expert, Nuxt Ecosystem Team member, and ambassador for Algolia, Cloudinary, and Supabase.

In this first part of the conversation, we explore topics including:

  • Why frontend security matters more than ever
  • What OWASP means for JavaScript developers
  • The purpose of Content Security Policy
  • Security differences between SPAs, SSR applications, and static websites
  • What a practical CSP setup can look like
  • Common misunderstandings around CORS
  • Security headers and rate limiting
  • How much protection frameworks should provide automatically
  • Lessons learned from building Nuxt Security
  • New risks introduced by AI coding tools

We only scratched the surface. This episode begins a broader series in which we will explore everything surrounding security in the JavaScript ecosystem, from everyday best practices to emerging threats and real-world vulnerabilities.

Subscribe to the JavaScript Master Podcast and join us for the next episodes!

#JavaScript #WebSecurity #FrontendSecurity #Nuxt #OWASP #ContentSecurityPolicy #CSP #CORS #CyberSecurity #WebDevelopment #GDE #JSMP #JavaScriptMasterPodcast

Podden och tillhörande omslagsbild på den här sidan tillhör Dariusz Kalbarczyk. Innehållet i podden är skapat av Dariusz Kalbarczyk och inte av, eller tillsammans med, Poddtoppen.